exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 213 RSS Feed

Files

Packet Storm New Exploits For November, 2011
Posted Dec 1, 2011
Authored by Todd J. | Site packetstormsecurity.com

This archive contains all of the 212 exploits added to Packet Storm in November, 2011.

tags | exploit
systems | linux
SHA-256 | 4ce4dae14067c705b24f6a65f2b6a121fc4cc0c48d373b45b008d48685e82e05
IBM Lotus Domino Authentication Bypass
Posted Nov 30, 2011
Authored by Alexey Sintsov

IBM Lotus Domino versions 8.5.3 and 8.5.2 FP3 suffer from an authentication bypass vulnerability.

tags | exploit, bypass
advisories | CVE-2011-1519
SHA-256 | a2ec180c7015b665a8c09c5c87f819d86fe11a21748572b331a213d5403e5704
PHP Inventory 1.3.1 SQL Injection
Posted Nov 30, 2011
Authored by Stefan Schurtz

PHP Inventory version 1.3.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, php, sql injection
advisories | CVE-2009-4595, CVE-2009-4596, CVE-2009-4597
SHA-256 | 8ebe11c2190eb6eb4bb69b19db6d857a31629633ee830ea142db005190e42979
WordPress Flash Album Gallery Cross Site Scripting
Posted Nov 30, 2011
Authored by Am!r | Site irist.ir

The WordPress flash-album-gallery plugin suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | c688bb0b8f202c7a6bc310458f0bf58c3de2ea24bb5ddaaaa3c66c574d93f542
WordPress 1 JQuery Photo Gallery Slideshow Flash Cross Site Scripting
Posted Nov 30, 2011
Authored by Am!r | Site irist.ir

The WordPress 1-jquery-photo-gallery-slideshow-flash plugin suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2558a4d7ede8efa08cbd2de4b5277d0eb7759f89ded4b6086846dece6ddfac02
Serv-U FTP Server Jail Break
Posted Nov 30, 2011
Authored by Kingcope

Serv-U FTP server suffers from a remote jail breaking vulnerability.

tags | exploit, remote
SHA-256 | 69f0832074081c550ccae5d7f3afc1b4046cc0632090e235f13b3fc2d70e5155
ProFTPd / FreeBSD ftpd Remote Root
Posted Nov 30, 2011
Authored by Kingcope

Remote root exploit for FreeBSD ftpd and ProFTPd on FreeBSD. It leverages the fact that /etc and /lib can be modified inside of the chroot.

tags | exploit, remote, root
systems | freebsd
SHA-256 | f59b24d7a9bf8446fb65b25ad7046e1b91fd2198e39bf16f0a7f6d2431d9e848
Voxsmart VoxRecord Control Centre 2.7 SQL Injection
Posted Nov 30, 2011
Authored by Piotr Duszynski

Voxsmart VoxRecord Control Centre version 2.7 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | b233d577e2af4bd51137e11dd2e49abfffaaecec046f5ee3bb29090373476e66
Java Applet Rhino Script Engine Remote Code Execution
Posted Nov 30, 2011
Authored by sinn3r, Michael Schierl, juan vazquez, Edward D. Teach | Site metasploit.com

This Metasploit module exploits a vulnerability in the Rhino Script Engine that can be used by a Java Applet to run arbitrary Java code outside of the sandbox. The vulnerability affects version 7 and version 6 update 27 and earlier, and should work on any browser that supports Java (for example: IE, Firefox, Google Chrome, etc).

tags | exploit, java, arbitrary
advisories | CVE-2011-3544, OSVDB-76500
SHA-256 | d91e779ec520d6b5000796fbb5510410cdd34ecb929017aa6bdbbf0c838eed04
CTEK SkyRouter 4200 / 4300 Command Execution
Posted Nov 30, 2011
Authored by savant42 | Site metasploit.com

This Metasploit module exploits an unauthenticated remote root vulnerability within CTEK SkyRouter versions 4200 and 4300.

tags | exploit, remote, root
SHA-256 | 5e44a6afb2c0c358e26b3780e96612702111f90fcd3b8cfd6335fb6f309d516d
WikkaWiki 1.3.2 Code Execution / Shell Upload / SQL Injection
Posted Nov 30, 2011
Authored by EgiX

WikkaWiki versions 1.3.2 and below suffers from remote SQL injection, unrestricted file upload, arbitrary file download, arbitrary file deletion, remote code execution and cross site request forgery vulnerabilities.

tags | exploit, remote, arbitrary, vulnerability, code execution, sql injection, file upload, csrf
advisories | CVE-2011-4448, CVE-2011-4449, CVE-2011-4450, CVE-2011-4451, CVE-2011-4452
SHA-256 | f5f16ff3f59901b3991fb94563c0b39bd9eee2fd825e6f8c81aec203ea470e7a
GOM Player 2.1.33.5071 Stack Buffer Overflow
Posted Nov 30, 2011
Authored by Debasish Mandal

GOM Player version 2.1.33.5071 unicode stack buffer overflow exploit that creates a malicious .asx file.

tags | exploit, overflow
SHA-256 | 971fa225476af793630fed50acafc906d65f2a06c6b21985a2ea4f591586bbfe
Bugbear FlatOut 2005 Buffer Overflow
Posted Nov 30, 2011
Authored by Silent Dream

Bugbear FlatOut 2005 buffer overflow exploit that creates a malicious .bed file.

tags | exploit, overflow
SHA-256 | bc3c99f35356951f3633ebafa0c89c0c906268e205967ca4a6f14d98b4168b1e
MS11-080 Afd.sys Privilege Escalation
Posted Nov 30, 2011
Authored by Matteo Memelli

MS11-080 privilege escalation exploit that leverages the fact that afd.sys does not properly validate user-mode input passed to kernel-mode.

tags | exploit, kernel
advisories | CVE-2011-2005
SHA-256 | 050ef4e20cffa5096df95d3a92d67ec15bef3ea3848cd5b8824bbec9e2cb4338
Avid Media Composer 5.5 Stack Buffer Overflow
Posted Nov 30, 2011
Authored by Nick Freeman | Site security-assessment.com

The AvidPhoneticIndexer.exe network daemon that ships with Avid Media Composer version 5.5 suffers from a remote stack buffer overflow. This was demonstrated at Ruxcon 2011 in the Hacking Hollywood talk. Included in this archive are the advisory and a Metasploit module.

tags | exploit, remote, overflow
systems | linux
SHA-256 | a6100e77da08ab7504d889909384925c152f4a923056b91aef442070ec7d5eeb
StoryBoard Quick 6 Stack Buffer Overflow
Posted Nov 30, 2011
Authored by Nick Freeman | Site security-assessment.com

StoryBoard Quick version 6 suffers from a file format stack buffer overflow. This was demonstrated at Ruxcon 2011 in the Hacking Hollywood talk. Included in this archive are the advisory, a proof of concept and a Metasploit module.

tags | exploit, overflow, proof of concept
systems | linux
SHA-256 | a58071791bae0e9b02ab74ae8bc27fb0a782edd806f7f95a6330d6c8d53fb41c
Muster Render Farm Management System 6.1.6 Arbitrary File Download
Posted Nov 30, 2011
Authored by Nick Freeman | Site security-assessment.com

Muster Render Farm Management System version 6.1.6 suffer from an arbitrary file download issue due to a directory traversal vulnerability. This was demonstrated at Ruxcon 2011 in the Hacking Hollywood talk. The advisory in this archive includes exploitation details.

tags | exploit, arbitrary
systems | linux
SHA-256 | 4c7c5caf872d4ace08b11d687019c73a366d5da96d3cb3fa5d8590c61b7d691a
Final Draft 8 Stack Buffer Overflow
Posted Nov 30, 2011
Authored by Nick Freeman | Site security-assessment.com

Final Draft version 8 suffers from a file format stack buffer overflow. This was demonstrated at Ruxcon 2011 in the Hacking Hollywood talk. Included in this archive are the advisory, a proof of concept and a Metasploit module.

tags | exploit, overflow, proof of concept
systems | linux
SHA-256 | ac3e47d5874fd1d4daad7534970506cf6afc9f213d1d90f20086b45e813dcbbd
Schok Creative SQL Injection
Posted Nov 30, 2011
Authored by nGa Sa Lu

Sites created by Schok Creative suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7dc0055c5274ec7437bf95c76e36a43b0359c3cbaf719121cde6e20ed1e6a1f9
3S CoDeSys 3.4 SP4 Patch 2 Overflows / NULL Pointers
Posted Nov 30, 2011
Authored by Luigi Auriemma | Site aluigi.org

3S CoDeSys versions 3.4 SP4 Patch 2 and below suffer from integer overflow, stack overflow, folder creation and multiple NULL pointer vulnerabilities.

tags | exploit, overflow, vulnerability
systems | linux
SHA-256 | 9f18a5df23671b7b00bdf05e10758b4e56ae625a309b1451df702bc5cf7e4932
Video Girls BiZ Video Chat Script Cross Site Scripting / SQL Injection
Posted Nov 30, 2011
Authored by Eyup CELIK

Video Girls BiZ Video Chat script suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | f08affdc5afc926fe3dc84284f7bab1c69b9a826f7b4c5b18d73b619062ce184
ExpressionEngine 2.2.2 / CodeIgniter 2.0.3 Cross Site Scripting
Posted Nov 30, 2011
Authored by Dr. Marian Ventuneac

ExpressionEngine version 2.2.2 and CodeIgniter version 2.0.3 suffer from filter bypass and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2011-4025
SHA-256 | fdab17029ae48b80689e4ddd515edc23100d07a8f55741743dc18b289e5b7a22
Ajax Script Cross Site Scripting / SQL Injection
Posted Nov 30, 2011
Authored by Eyup CELIK

Ajax Script suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 4b9b807cf31978b23900da02089db7c0593e9b3d9d8818e73b8619fa6d5324e1
Toshiba.com / Compaq.com Cross Site Scripting
Posted Nov 30, 2011
Authored by Sony

Toshiba.com and Compaq.com suffer from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | d20994a6ef3ff7ce5d7076c9ff08e0cb8eff2bb0a686c23fd54a38d799d17bc5
ModenaCam SQL Injection / Cross Site Scripting
Posted Nov 30, 2011
Authored by Eyup CELIK

ModenaCam, the Adult Turnkey Flash Live Chat Software script, suffers from remote SQL injection and cross site scripting vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
systems | linux
SHA-256 | effbed27188e2b0a4ceac3cf54c68aac13e6f3a4b929f812bc21ab058843771d
Page 1 of 9
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close