what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 352 RSS Feed

Files

GreenBrowser 6.1.x Cross Site Scripting
Posted Mar 28, 2012
Authored by Lostmon | Site lostmon.blogspot.com

GreenBrowser suffers from dialog and stored cross site scripting vulnerabilities. Versions 6.1.0117 and 6.1.0216 are affected.

tags | exploit, vulnerability, xss
SHA-256 | 52011797f6cf6b3020e9528439fbb81b5f61d8b3df82e16e190aca42efcb4e80
NextBBS 0.6.0 Authentication Bypass / SQL Injection / XSS
Posted Mar 28, 2012
Authored by Janek Vind aka waraxe | Site waraxe.us

NextBBS version 0.6.0 suffers from authentication bypass, cross site scripting, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | bfa83da9859d83d6988d38e9d8dc4e00aea5881410d054635c38bf926bc80c44
WordPress Integrator 1.32 Cross Site Scripting
Posted Mar 28, 2012
Authored by Stefan Schurtz

WordPress Integrator plugin version 1.32 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 226dc0865f1e4637a651cc57b54000997a519d9ef7a21654f2c356f06f380d22
IP.Board Add-on IP.Gallery 4.2.1 Cross Site Scripting
Posted Mar 28, 2012
Authored by Sony, Flexxpoint

IP.Board Add-on IP.Gallery version 4.2.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 90c47186ae1674d5115aa9b5aa199e83a70e3cd3652f114d5d4cfa401a38b202
Safari For Windows 5.1.5 URL window.open() Spoof
Posted Mar 28, 2012
Authored by Lostmon | Site lostmon.blogspot.com

Safari for Windows versions 5.1.5 and below URL window.open() spoofing exploit.

tags | exploit, spoof
systems | windows
SHA-256 | fa47711147826c3af24200dac00cf3b0e261d6aac3b5014aeeb8cecd5a70ee04
Serido CMS SQL Injection
Posted Mar 28, 2012
Authored by the_cyber_nuxbie

Serido CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 8f54cea7fe56f563e5f9f54ce1d3096211202437785c28a2bb98ba94f0398d21
Matthew1471s ASP BlogX Cross Site Scripting
Posted Mar 28, 2012
Authored by demonalex

Matthew1471s ASP BlogX suffers from a cross site scripting vulnerability.

tags | exploit, xss, asp
SHA-256 | 278ceb4d4521a0d480bdb5620b3f83a5315dd44c0864b48c673fe27f962b2c8f
MyBB 1.6.6 Cross Site Scripting / SQL Injection
Posted Mar 27, 2012
Authored by Aditya Modha

MyBB version 1.6.6 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 1c05d3a8ad5d3b1a5d24d5c58e27e647e137cbad96576db30cdb622ac4ada965
PcwRunAs 0.4 Password Obfuscation Design Flaw
Posted Mar 26, 2012
Authored by otr

The PcwRunAs software available from the PC-Welt website is prone to a trivial password recovery attack that allows local users to obtain passwords encrypted with the pcwRunAsGui.exe. pcwRunAs versions 0.4 and below are affected.

tags | exploit, local
advisories | CVE-2012-1793
SHA-256 | 811b545d5083c227c56986dbdeeac60ef0a1b6690230618e3d3b76f311c4ab12
Family CMS 2.9 Cross Site Scripting / Cross Site Request Forgery
Posted Mar 26, 2012
Authored by Ahmed Elhady Mohamed

Family CMS versions 2.9 and below suffer from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 1ec7f405de63ef5f7838d32c96dbfa4b6d6603c64200b6d6fa5153eb534bef34
Wolf CMS 0.75 Persistent Cross Site Scripting
Posted Mar 26, 2012
Authored by Ivano Binetti

Wolf CMS versions 0.75 and below suffer from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | bf5531ebf0d1f42a147d86f362d0405a209a4ad6e8e3ce3b8be40adb10d4cde7
Ricoh DC DL-10 SR10 FTP USER Command Buffer Overflow
Posted Mar 26, 2012
Authored by sinn3r, Julien Ahrens | Site metasploit.com

This Metasploit module exploits a vulnerability found in Ricoh DC's DL-10 SR10 FTP service. By supplying a long string of data to the USER command, it is possible to trigger a stack-based buffer overflow, which allows remote code execution under the context of the user. Please note that in order to trigger the vulnerability, the server must be configured with a log file name (by default, it's disabled).

tags | exploit, remote, overflow, code execution
advisories | OSVDB-79691
SHA-256 | 2e39652db0079e5ca51125d0179fc236f418207928058994109116189eadb542
UltraVNC 1.0.2 Client (vncviewer.exe) Buffer Overflow
Posted Mar 26, 2012
Authored by noperand | Site metasploit.com

This Metasploit module exploits a buffer overflow in UltraVNC Viewer 1.0.2 Release. If a malicious server responds to a client connection indicating a minor protocol version of 14 or 16, a 32-bit integer is subsequently read from the TCP stream by the client and directly provided as the trusted size for further reading from the TCP stream into a 1024-byte character array on the stack.

tags | exploit, overflow, tcp, protocol
advisories | CVE-2008-0610, OSVDB-42840
SHA-256 | b357e9030ba561108d1415577377c438445c6d1ccdf5a6b60eef2ab3f927b9c6
FreePBX 2.10.0 / 2.9.0 callmenum Remote Code Execution
Posted Mar 26, 2012
Authored by muts | Site metasploit.com

This Metasploit module exploits FreePBX version 2.10.0,2.9.0 and possibly older. Due to the way callme_page.php handles the 'callmenum' parameter, it is possible to inject code to the '$channel' variable in function callme_startcall in order to gain remote code execution. Please note in order to use this module properly, you must know the extension number, which can be enumerated or bruteforced, or you may try some of the default extensions such as 0 or 200. Also, the call has to be answered (or go to voice). Tested on both Elastix and FreePBX ISO image installs.

tags | exploit, remote, php, code execution
SHA-256 | 732f9a89390a847e9a30d1b733961bd71e76e38457ac805770011388b929d0cc
CheckPageRankGoogle Cross Site Scripting
Posted Mar 25, 2012
Authored by Girish Shrimali

Checkpagerankgoogle.com suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ee0303b63281ce4c2c26227f5bc2666eac841f26c64ccf604363ce40901baa6f
Geeklog 1.8.1 SQL Injection
Posted Mar 25, 2012
Authored by HELLBOY

Geeklog version 1.8.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 9be3e7153df67b33b254726a14a901951aaaba4751f8049fd80f5b1eb6da025f
vBshop Persistent Cross Site Scripting
Posted Mar 25, 2012
Authored by ToiL

vBshop suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | d4a6811d6fb5bac7dbc3fdde83a891132b9c2f843ed4d0dd91eb279b0283ae47
Pale Moon Web Browser 11.0 Denial Of Service
Posted Mar 25, 2012
Authored by eidelweiss

Pale Moon Web Browser version 11.0 suffers from a multiple looping denial of service vulnerability.

tags | exploit, web, denial of service
SHA-256 | 40561a779d1b6656164dae1c91c66170fb40b3a209cc2de7e38e82b7eb790a39
Otuz8 Medya Cross Site Scripting
Posted Mar 25, 2012
Authored by V4rcyion

Otuz8 Medya suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 0c3d7e759f5842190060b4b859db8cfdfd3d3e5b8c4e3e3e8c999f3059f2d896
Validate.icq.com Cross Site Scripting
Posted Mar 25, 2012
Authored by Sony, Flexxpoint

Validate.icq.com suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ccacf2ce466f55826ad427e0bf970ca5cfdd882f0cc43dd33c48bdd083b5a97b
FBLike Script Cross Site Scripting
Posted Mar 25, 2012
Authored by Crim3R

FBLike Script suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | c71e8559d3436f05fed29184dce0f98281b30b1685e4fa19b6b6246ec5639d21
PHP 5.4.0 Denial Of Service
Posted Mar 24, 2012
Authored by ls

PHP version 5.4.0 built-in web server denial of service proof of concept exploit.

tags | exploit, web, denial of service, php, proof of concept
SHA-256 | bbfd3425e200f20aede920fb93f171459ebc22c83495b9e14ad46cef5fb558db
Event Calendar PHP 1.0 Cross Site Scripting
Posted Mar 24, 2012
Authored by 3spi0n

Event Calendar PHP 1.0 suffers from a cross site scripting vulnerability. Version 1.1 fixes this issue.

tags | exploit, php, xss
SHA-256 | da5cb4722a4744a9001176ef2a9c67350d54eb420e64cc3e33a32ea6f03e3c76
Laoy8! 3.0sp1 Cross Site Scripting
Posted Mar 24, 2012
Authored by Ali.Erroor

Laoy8! CMS version 3.0sp1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 4930a19b764cac7eda59e68e1a8624d9d7c53390ff842362f47a4b2479ea53cc
vBulletin vBShout 6.0.5 Cross Site Scripting
Posted Mar 24, 2012
Authored by d3v1l

vBulletin vBShout module versions 6.0.5 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 462691bf6e33cb4da99f73fd68d72c50e99cf6cb8e3203bd504dcf8a334e3836
Page 3 of 15
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
North Korean Hackers Hijack Antivirus Updates For Malware Delivery
Posted Apr 24, 2024

tags | headline, hacker, government, malware, flaw, cyberwar, military, north korea
CISA Warns Of Windows Print Spooler Flaw After Microsoft Sees Russian Exploitation
Posted Apr 24, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar
US Charges Iranians With Cyber Snooping On Government, Companies
Posted Apr 24, 2024

tags | headline, hacker, government, privacy, usa, cyberwar, spyware, iran
TensorFlow AI Models At Risk Due To Keras API Flaw
Posted Apr 24, 2024

tags | headline, flaw
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close