what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 311 RSS Feed

Files

KMPlayer 3.2.0.19 DLL Hijack
Posted Apr 26, 2012
Authored by nImaarek

KMPlayer version 3.2.0.19 suffers from a DLL hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | e710953170f62944c95092c7d7f49e5821951feac65493d0dc8d7059e53707a9
Parallels PLESK 9.x Insecure Permissions
Posted Apr 26, 2012
Authored by Nicolas Krassas

Parallels PLESK version 9.x suffers from an insecure permissions vulnerability.

tags | exploit
SHA-256 | ed2521012c4e3be895f96bbdf69d5c6e700987738b89562f7bc01f25941cf0cb
WordPress Zingiri Web Shop 2.4.0 Cross Site Scripting
Posted Apr 26, 2012
Authored by Mehmet Ince

WordPress Zingiri Web Shop plugin versions 2.4.0 and below suffer from reflective and stored cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss
SHA-256 | 18ed50d1ec24690a1dd37bbe47a05297e810a1d475db1cbd2c532a9a4dbb6838
Microsoft MSN Hotmail Password Reset
Posted Apr 26, 2012
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Microsoft MSN Hotmail suffered from a password reset and setup vulnerability.

tags | exploit
SHA-256 | 49073ed7e6528aed6e2a1395224e58b80dc4adcd3daca681f9d673e3701cffb1
Ettercap NG 0.7.4 DLL Hijack
Posted Apr 26, 2012
Authored by nImaarek

Ettercap NG version 0.7.4 suffers from a DLL hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | d04c00509e1d3444d662e6b7f22e92825bfd705db741648e0c2385bed9551510
Shadow Stream Recorder 3.0.1.7 Buffer Overflow
Posted Apr 25, 2012
Authored by AlpHaNiX, b0telh0 | Site metasploit.com

This Metasploit module exploits a buffer overflow in Shadow Stream Recorder 3.0.1.7. Using the application to open a specially crafted asx file, a buffer overflow may occur to allow arbitrary code execution under the context of the user.

tags | exploit, overflow, arbitrary, code execution
SHA-256 | 8605d6b286358f8ebce3e864c8089ee88a7cec055a12349e1618003174c8d254
MS12-027 MSCOMCTL ActiveX Buffer Overflow
Posted Apr 25, 2012
Authored by unknown, sinn3r, juan vazquez | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in MSCOMCTL.OCX. It uses a malicious RTF to embed the specially crafted MSComctlLib.ListViewCtrl.2 Control as exploited in the wild on April 2012. This Metasploit module targets Office 2007 and Office 2010 targets. The DEP/ASLR bypass on Office 2010 is done with the Ikazuchi ROP chain proposed by Abysssec. This chain uses "msgr3en.dll", which will load after office got load, so the malicious file must be loaded through "File / Open" to achieve exploitation.

tags | exploit, overflow
advisories | CVE-2012-0158, OSVDB-81125
SHA-256 | 0b684caf70084bb5bcb079447d8379464ff2e3e928ee2d84beab044161baf6bb
WordPress Organizer 1.2.1 XSS / CSRF / Shell Upload
Posted Apr 25, 2012
Authored by MustLive

WordPress Organizer version 1.2.1 suffers from cross site request forgery, cross site scripting, and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, xss, csrf
SHA-256 | 5d7da27b984ced3d8195b475c086f6fa632941aa13a56de1779eb08cce7b634d
MoroccoTel Default Password
Posted Apr 25, 2012
Authored by Jerome Athias

MoroccoTel boxes suffer from an issue where there is a default password that can be used on the telnet server.

tags | exploit
SHA-256 | 15212df8a3a8d8b6ba16ec77025ef5e22d8dacfee6fd2ff769977b33b5b5fd46
Piwigo 2.3.3 Cross Site Scripting / Directory Traversal
Posted Apr 25, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Piwigo version 2.3.3 suffers from cross site scripting and directory traversal vulnerabilities.

tags | exploit, vulnerability, xss, file inclusion
advisories | CVE-2012-2208, CVE-2012-2209
SHA-256 | 170fe747de0161668180d3fcf82d6993ee1b0965b81a9d2d8dfc43b1af0b7d9e
mount.cifs chdir() File Identification
Posted Apr 25, 2012
Authored by Jesus Olmos Gonzalez

mount.cifs chdir() allows for arbitrary file identification as root. All versions prior to 5.4 are affected.

tags | exploit, arbitrary, root
SHA-256 | 1a07d210c27edc8b4cb7f1f1ad3579fd0a15fb1679968e8465902f2d88e2e7ae
Joomla Video Gallery Local File Inclusion / SQL Injection
Posted Apr 24, 2012
Authored by KedAns-Dz

The Joomla Video Gallery component suffers from local file inclusion and remote SQL injection vulnerabilities.

tags | exploit, remote, local, vulnerability, sql injection, file inclusion
SHA-256 | 462e3a42ad4cdf7f3d4b4fc799263665b5f88d737088527e7db190630d754023
PHP Ticket System Beta 1 SQL Injection
Posted Apr 24, 2012
Authored by G13

PHP Ticket System Beta 1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
SHA-256 | f331b153861f4c95d8694429e29e08f749646cec6c2de5b128d953c29eb07810
RuggedCom Device Undocumented Backdoor
Posted Apr 24, 2012
Authored by jc

An undocumented backdoor account exists within all released versions of RuggedCom's Rugged Operating System (ROS®). The username for the account, which cannot be disabled, is "factory" and its password is dynamically generated based on the device's MAC address. Multiple attempts have been made in the past 12 months to have this backdoor removed and customers notified. Exploit included.

tags | exploit
advisories | CVE-2012-1803
SHA-256 | fb64f3c68bc6c2d150dfa801c3cc74442ea2352e08299729ea8753433d5ab22a
BeyondCHM 1.1 Buffer Overflow
Posted Apr 24, 2012
Authored by shinnai | Site shinnai.altervista.org

BeyondCHM version 1.1 suffers from a buffer overflow vulnerability when handling a specially crafted chm file. Proof of concept included.

tags | exploit, overflow, proof of concept
systems | linux
SHA-256 | 1f4140d1bd20cda3a4f39e3e694685f225a0d65e60da185fa2ca460418e79975
CMS By Hispanic Digital Network, Inc SQL Injection / Cross Site Scripting
Posted Apr 24, 2012
Authored by the_cyber_nuxbie

CMS By Hispanic Digital Network, Inc. suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | e0609b970a7a2371fc93de251413bd770167edbea45b1afe9330271db1a45913
Ettercap 0.7.4.1 DLL Hijack
Posted Apr 24, 2012
Authored by nImaarek

Ettercap version 0.7.4.1 suffers from a DLL hijacking vulnerability.

tags | exploit
systems | windows
SHA-256 | 0a44574fc1b60dc3699352b2c882fc1583f45dbb3776d25cff6a520d75cd30d8
Website Design Cardiff SQL Injection
Posted Apr 24, 2012
Authored by Th4 MasK

Website Deisgn Cardiff suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 9fb16c16ea10f1e8ab6415d84c27188754c2862797de36e6bc36d57da8055092
Mitsubishi.ru Cross Site Scripting / SQL Injection
Posted Apr 24, 2012
Authored by Ryuzaki Lawlet

Mitsubishi.ru suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | c4f9192ef7220609caa4d99bd7ed8867a4dc1456498243db2df42f5a17131299
ChurchCMS 0.0.1 SQL Injection
Posted Apr 23, 2012
Authored by G13

ChurchCMS version 0.0.1 suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | daf142bf714b4c86657eb17fad71cfb835dab67218e8b0d57cc94cd82c369f65
.NET Framework EncoderParameter Integer Overflow
Posted Apr 23, 2012
Authored by Yorick Koster | Site akitasecurity.nl

An integer overflow vulnerability has been discovered in the EncoderParameter class of the .NET Framework. Exploiting this vulnerability results in an overflown integer that is used to allocate a buffer on the heap. After the incorrect allocation, one or more user-supplied buffers are copied in the new buffer, resulting in a corruption of the heap.

tags | exploit, overflow
SHA-256 | 9f691c33118729de8b1118c45e101699844a3903353809ae5aaae2e5abda61ad
School Website Solutions Cross Site Scripting
Posted Apr 23, 2012

School Website Solutions suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 80af71695150018fd717350d968e6d200dcb7528844b325608fb32140f234a4d
ExponentCMS 2.0.5 Cross Site Scripting / SQL Injection
Posted Apr 23, 2012
Authored by Onur YILMAZ | Site netsparker.com

ExponentCMS version 2.0.5 suffers from cross site scripting and remote blind SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 68603c7e8c2f5997c0f69c3794e2233a415b93ed2b8acfd1beee701a907b284c
Mobipocket Reader 6.2 Build 608 Buffer Overflow
Posted Apr 23, 2012
Authored by shinnai | Site shinnai.altervista.org

Mobipocket Reader version 6.2 build 608 suffers from a buffer overflow vulnerability. Proof of concept included.

tags | exploit, overflow, proof of concept
SHA-256 | 956ac848bb2710f1365550adfff0b8787d1dfb621595612c0d1b192087b80cb7
SumatraPDF 2.0.1 Memory Corruption
Posted Apr 23, 2012
Authored by shinnai | Site shinnai.altervista.org

SumatraPDF version 2.0.1 suffers from chm and mobi file memory corruption vulnerabilities. Proof of concept included.

tags | exploit, vulnerability, proof of concept
systems | linux
SHA-256 | 2c48263ca242c08c83e3159ab0488a34d4ec0b9ed8c46ee7db29a49caef65b02
Page 4 of 13
Back23456Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close