what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 151 - 175 of 433 RSS Feed

Files

WHCMS 5.0.3 Remote File Inclusion
Posted Jun 19, 2012
Authored by EL-KAHINA

WHCMS version 5.0.3 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 532e03e38b10d3f50c3d381338ca5d1080316250f117137d65fe8c59a7e2d019
Sana Net SQL Injection
Posted Jun 19, 2012
Authored by Black Hat Group

Sana Net suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | d491a5a72f433e70dc437aad5c7566578adb0b5c61241911fd93e1130630f84f
Fireshop SQL Injection
Posted Jun 19, 2012
Authored by Black Hat Group

Fireshop suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 36d870fb070fb835a26adc1353be0922620e046bd24f7e31f4e19c3ade9e55cd
Sonna SQL Injection
Posted Jun 19, 2012
Authored by Black Hat Group

Sonna suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 3e384e602123e1e3714cb3a6de449d3115f1eb9f1d640ccfb070cff8cf0d70aa
ASP Content Management Database Disclosure
Posted Jun 19, 2012
Authored by indoushka

ASP Content Management suffers from a remote database disclosure vulnerability.

tags | exploit, remote, asp, info disclosure
SHA-256 | ed2c1c995ba55abc3d684e158935240fbf5549efa2590b99e3a007e08eb041b7
Pro Clan Manager 0.4.2 Administrative Bypass / Shell Upload
Posted Jun 19, 2012
Authored by indoushka

Pro Clan Manager version 0.4.2 suffer from administrative bypass and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, bypass
SHA-256 | 91de8e3281c1f4f38ec58022b3f86bbd3170212247a3c4bcacc892b75a42aa35
EZHomeTech EzServer 6.4.017 Stack Buffer Overflow
Posted Jun 19, 2012
Authored by modpr0be | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in the EZHomeTech EZServer. If a malicious user sends packets containing an overly long string, it may be possible to execute a payload remotely. Due to size constraints, this module uses the Egghunter technique.

tags | exploit, overflow
SHA-256 | 2bc92ff43f6bcca9c19f782162fc5db7f333fc90bad8a57b6c286fccae52a802
Airlock WAF 4.2.4 Bypass
Posted Jun 19, 2012
Authored by G. Wagner | Site sec-consult.com

The Airlock WAF protection can be completely bypassed by using overlong UTF-8character representations of the NUL character such as C0 80, E0 80 80 and F080 80 80. During the tests no internal knowledge of the WAF was known, but it is suspected that the UTF-8 decoder fails to reject the overlong NUL byte character representations and they get decoded as U+0000 later on. Further the WAF would not perform any checks for attack patterns after the NUL byte. Versions 4.2.4 and below are affected.

tags | exploit
SHA-256 | 4500f9de8c3478095642ee54e1fc94fcf7d2f146d8b89ff5f68fd0fa5d527f81
Ezhometech Ezserver 6.4 Stack Overflow
Posted Jun 19, 2012
Authored by modpr0be

Ezhometech Ezserver versions 6.4 and below stack buffer overflow exploit that binds a shell to port 4444.

tags | exploit, overflow, shell
SHA-256 | 0a3c7b30433e99d4e5b31ad439b1616f357b9a2b87934bff537c85f76e8698e9
Squiz CMS 4.6.3 XXE Injection / Cross Site Scripting
Posted Jun 18, 2012
Authored by Nadeem Salim | Site senseofsecurity.com.au

Squiz CMS version 4.6.3 suffers from cross site scripting and XXE injection vulnerabilities.

tags | exploit, vulnerability, xss, xxe
SHA-256 | a5d045b3aad07ff6c6442d788cf3530feb8b0422a99a5af1dae6dda396024529
WordPress LB Mixed Slideshow 1.0 Shell Upload
Posted Jun 18, 2012
Authored by Sammy FORGIT

WordPress LB Mixed Slideshow plugin version 1.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 05d1ff86d15d4c018bc701f3b912dbda44ddada39fafab1e62575e473e009971
WordPress Famous 2.0.5 Shell Upload
Posted Jun 18, 2012
Authored by Sammy FORGIT

WordPress Famous theme version 2.0.5 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 5cd23143dda2991fa8b54bad24336fde593bf11003add82671ad05be651816d2
VANA CMS SQL Injection
Posted Jun 18, 2012
Authored by Black Hat Group

VANA CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 06f4bc981b8d0c7290c0f3d2af444d55400dc6e92ccfa1464b27166a7ed92ba7
WordPress Lim4wp 1.1.1 Shell Upload
Posted Jun 18, 2012
Authored by Sammy FORGIT

WordPress Lim4wp plugin version 1.1.1 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | bdd83eb33020bf673d8c201bed0edee4aea04fd587fad2b42688292c7b805cc7
WordPress Wp-ImageZoom 1.0.3 File Disclosure
Posted Jun 18, 2012
Authored by Sammy FORGIT

WordPress Wp-ImageZoom plugin version 1.03 suffers from a remote file disclosure vulnerability.

tags | exploit, remote, info disclosure
SHA-256 | 313fae93536b657222df93e542a161ff4e99e670f7fcc788a126bd30970b4474
WordPress Deep-Blue 1.9.2 Shell Upload
Posted Jun 18, 2012
Authored by Sammy FORGIT

WordPress Deep-Blue theme version 1.9.2 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 655fa08681c7b44b6899577f403fd689e810e5138a16b53311a249704bc54503
Bricolage 1.x SQL Injection / Cross Site Scripting
Posted Jun 18, 2012
Authored by r007k17-w

Bricolage version 1.x suffers from persistent cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 648f270968361f02a75713be4218de41297130fcbab5f3d51e86d905c491399c
MyTickets Blind SQL Injection
Posted Jun 18, 2012
Authored by al-swisre

MyTickets versions 1 through 2.0.8 suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 99fc0500b3e38cf669b96c02099379cc481addcdb679c1271958420f61af0d62
Total Video Player 1.31 Proof Of Concept
Posted Jun 18, 2012
Authored by 0dem

Total Video Player version 1.31 crash proof of concept denial of service exploit that creates malicious files.

tags | exploit, denial of service, proof of concept
SHA-256 | 50826852f4723c4697c5342a471db0766e94f72ffba3dc55768b3c1d68c3014d
PHP apache_request_headers Function Buffer Overflow
Posted Jun 17, 2012
Authored by juan vazquez, Vincent Danen | Site metasploit.com

This Metasploit module exploits a stack based buffer overflow in the CGI version of PHP 5.4.x before 5.4.3. The vulnerability is due to the insecure handling of the HTTP headers. This Metasploit module has been tested against the thread safe version of PHP 5.4.2, from "windows.php.net", running with Apache 2.2.22 from "apachelounge.com".

tags | exploit, web, overflow, cgi, php
systems | windows
advisories | CVE-2012-2329, OSVDB-82215
SHA-256 | 9911ce27bffaa90bdbd0d7a764559440c9b73d2a107c14d2ddcf46c3708a6749
QNAP Command Injection
Posted Jun 17, 2012
Authored by Phil Taylor, Nadeem Salim | Site senseofsecurity.com.au

QNAP Turbo NAS with firmware versions 3.6.1 Build 0302T and below suffer from a command injection vulnerability that allows for remote code execution.

tags | exploit, remote, code execution
SHA-256 | bcec74851c024f2e1466935f495fd1687810e39d50b44f12aa001bc14964e143
Joomla hwdVideoShare Shell Upload
Posted Jun 17, 2012
Authored by Sammy FORGIT

Joomla hwdVideoShare version r805 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | bc1e6119f2ed610cbf46770b53e894f80bf571ef0fd6dd76866a7970a5544ce0
Expressive SQL Injection
Posted Jun 17, 2012
Authored by Taurus Omar

Expressive suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 719742cd414eeb3533f6a8fe09ad8f2f72d205bbf4046d2802e193d710e842d7
Gate49 SQL Injection
Posted Jun 17, 2012
Authored by Taurus Omar

Gate49 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 26da9555ed1f769d448d67b2816b5465620fa020b873bdf5b302314bc644eab4
Glucone SQL Injection
Posted Jun 17, 2012
Authored by Taurus Omar

Glucone suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 6b6c790953a313e47f767bcbf9356d4021c0adab153cda27758fe04f8af292ce
Page 7 of 18
Back56789Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Life Imitates xkcd Comic As Florida Gang Beats Crypto Password From Retiree
Posted Sep 20, 2024

tags | headline, cybercrime, data loss, cryptography
1 In 10 Orgs Dumping Their Security Vendors After CrowdStrike Outage
Posted Sep 20, 2024

tags | headline, denial of service
Cyber Crooks Strut Away With Haute Couture Harvey Nichols Data
Posted Sep 20, 2024

tags | headline, hacker, privacy, britain, cybercrime, data loss, fraud
Noise Storms: Massive Amounts Of Spoofed Web Traffic Linked To China
Posted Sep 20, 2024

tags | headline, china
Tor Network Denies Report That Anonymity Is Completely Canceled
Posted Sep 20, 2024

tags | headline, government, privacy, cryptography
Marko Polo Hackers Found To Be Running Dozens Of Scams
Posted Sep 20, 2024

tags | headline, hacker, cybercrime, fraud, phish, cryptography
Re-Opened Three Mile Island Will Power AI Datacenters Under New Deal
Posted Sep 20, 2024

tags | headline, microsoft, botnet
Social Media Users Lack Control Over Data Used By AI, US FTC Says
Posted Sep 19, 2024

tags | headline, government, privacy, usa, data loss, botnet
Hackers Demand $6 Million From Seattle Airport Operators
Posted Sep 19, 2024

tags | headline, hacker, cybercrime, data loss, fraud, cryptography
Recent WhatsUp Gold Vulnerabilities Possibly Exploited In Ransomware Attacks
Posted Sep 19, 2024

tags | headline, malware, cybercrime, flaw, cryptography
View More News →
packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close