what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 158 RSS Feed

Files

Nagios NRPE 2.13 Code Execution
Posted Feb 22, 2013
Authored by Rudolph Pereira | Site occamsec.com

Nagios NRPE versions 2.13 and below suffer from a remote command execution vulnerability.

tags | exploit, remote
advisories | CVE-2013-1362
SHA-256 | e554055ae18cd9fe6bcd14421d423114eca4f1e47b88e319df4e7a81bb4acf86
Samsung Galaxy S3 Screen-Lock Bypass
Posted Feb 22, 2013
Authored by MTI Technology | Site mti.com

The Samsung Galaxy S3 w/ Android version 4.1.2 suffers from a bypass vulnerability due to S-Voice allowing the launch of any command even when the screen is locked.

tags | exploit, bypass
SHA-256 | f859a2a4bfd30be0e55663fe5c258853b5ad3a563064a6354107e8e25a8fc7cc
Skype Community Cross Site Scripting
Posted Feb 22, 2013
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Skype Community suffers from a mail encoding vulnerability that allows for cross site scripting.

tags | exploit, xss
SHA-256 | f875298ab79c2bac8df467b2c5020347cac0994efeb657b8bd749495b90c5e33
PHPMyGallery 1.51.010 XSS / Local File Disclosure
Posted Feb 21, 2013
Authored by TheMirkin

PHPMyGallery versions 1.51.010 and below suffer from cross site scripting and local file disclosure vulnerabilities.

tags | exploit, local, vulnerability, xss, file inclusion
SHA-256 | 20d47589fda76b6266aba44c1e813c04372ac15ad0236197863aa8da862bb577
Web Cookbook File Disclosure / SQL Injection
Posted Feb 21, 2013
Authored by cr4wl3r

Web Cookbook suffers from file disclosure and remote SQL injection vulnerabilities.

tags | exploit, remote, web, vulnerability, sql injection, info disclosure
SHA-256 | 190be9195cee32cae8fedc09d268ca560d5320e5f2cff88ab751a247c7d6146b
OpenEMR 4.1.1 Cross Site Scripting
Posted Feb 21, 2013
Authored by LiquidWorm | Site zeroscience.mk

OpenEMR version 4.1.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 2794e272098c49fab5ad0608f9d0bb8abb46fa3cfb850da04587f0f744cfa619
EasyWebScripts eBay Clone Script SQL Injection
Posted Feb 21, 2013
Authored by 3spi0n

EasyWebScripts eBay Clone Script suffers from remote SQL injection and CRLF injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | b043a94f844af4460c90d1bbb5fd0e0f1838373d2498784f9ce3b6c6d0231de2
Alt-N MDaemon WorldClient / WebAdmin Cross Site Request Forgery
Posted Feb 21, 2013
Authored by Demetris Papapetrou, QSecure | Site qsecure.com.cy

Alt-N MDaemon version 13.0.3 WorldClient and WebAdmin applications suffer from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 7254dc66cd6fba6e9a6eb7e9d46b3ad55c8a16813b7770255f61f633561438bb
WordPress Pretty Link 1.6.3 Cross Site Scripting
Posted Feb 21, 2013
Authored by hip

WordPress Pretty Link plugin version 1.6.3 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2013-1636
SHA-256 | 0bd94f72723b7408dcb28b0101289332e56f5ec23c7de0a8015324251cd66bfc
Alt-N MDaemon WorldClient Predictable Session ID
Posted Feb 21, 2013
Authored by Demetris Papapetrou, QSecure | Site qsecure.com.cy

The Alt-N MDaemon version 13.0.3 WorldClient application suffers from a predictable session identifier vulnerability.

tags | exploit
SHA-256 | 92424873721cd173dc332823577d395adb3e123a0b90d2cd1514c100d2e80883
Alt-N MDaemon Email Body Cross Site Scripting
Posted Feb 21, 2013
Authored by Demetris Papapetrou, QSecure | Site qsecure.com.cy

Alt-N MDaemon version 13.0.3 suffers from a cross site scripting vulnerability in the email body due to a lack of sanitization.

tags | exploit, xss
SHA-256 | 7325b220864d0b6ff380a077b29aa8c7293ee9eaa3cbb5bbf03f8dd6edefd13d
Alt-N MDaemon WorldClient Username Enumeration
Posted Feb 21, 2013
Authored by Demetris Papapetrou, QSecure | Site qsecure.com.cy

The Alt-N MDaemon version 13.0.3 WorldClient application suffers from a username enumeration vulnerability based on responses provided.

tags | exploit
SHA-256 | 88ffc39eb1145981a8577ef2cd3a701922e79b7e248031243a1d54728446a564
Alt-N MDaemon WebAdmin Remote Code Execution
Posted Feb 21, 2013
Authored by Demetris Papapetrou, QSecure | Site qsecure.com.cy

The Alt-N MDaemon version 13.0.3 WebAdmin application suffers from a remote code execution vulnerability via the user account import facility.

tags | exploit, remote, code execution
SHA-256 | b1e0f846c97665c28984ae715b8e4178e351676b7e1aef82d5ac59c0302500d2
Alt-N MDaemon WorldClient Credential Disclosure
Posted Feb 21, 2013
Authored by Demetris Papapetrou, QSecure | Site qsecure.com.cy

The Alt-N MDaemon version 13.0.3 WorldClient application suffers from a credential disclosure vulnerability. This is possible because the application replies to a request with a response that contains the credentials in an encoded (reversible) format.

tags | exploit, info disclosure
SHA-256 | 5e526cfd34acc8dc5cebe4e940c88c797073c12adce735bb8dc9adf90132aebf
glFusion 1.2.2 Cross Site Scripting
Posted Feb 21, 2013
Authored by High-Tech Bridge SA | Site htbridge.com

glFusion version 1.2.2 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2013-1466
SHA-256 | 6306b577c5a62df9e36abe88ce8b0307d8747c5119f8cf35f07026923b542faa
phpMyRecipes 1.2.2 SQL Injection
Posted Feb 21, 2013
Authored by cr4wl3r

phpMyRecipes version 1.2.2 remote SQL injection exploit.

tags | exploit, remote, sql injection
SHA-256 | 48cf9d477ec7a80c51ed5ab37dd272196f3a99397e30828b2d1164825dd48df9
RTTucson Quotations Database Authentication Bypass
Posted Feb 21, 2013
Authored by cr4wl3r

RTTucson Quotations Database Script suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | cdcaa384c92df2bf334a9b66417054e96b8f61a54b8d21f9c18d3692cc3dc645
Zenphoto 1.4.4.1 Blind SQL Injection
Posted Feb 20, 2013
Authored by Hossein Nsn

Zenphoto version 1.4.4.1 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | d966ea31e8b17b2b96cb9927385cb3b427eac99bb64c3cc081daaa582daaf212
BigAnt Server 2 SCH And DUPF Buffer Overflow
Posted Feb 20, 2013
Authored by juan vazquez, Hamburgers Maccoy | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in BigAnt Server 2.97 SP7. The vulnerability is due to the dangerous usage of strcpy while handling errors. This module uses a combination of SCH and DUPF request to trigger the vulnerability, and has been tested successfully against version 2.97 SP7 over Windows XP SP3 and Windows 2003 SP2.

tags | exploit, overflow
systems | windows
advisories | CVE-2012-6275, OSVDB-89344
SHA-256 | fd7a317c230213f8edc299a76b9d39aee9e244cbb2a205aa46a90b61823d7fee
BigAnt Server DUPF Command Arbitrary File Upload
Posted Feb 20, 2013
Authored by juan vazquez, Hamburgers Maccoy | Site metasploit.com

This Metasploit module exploits an arbitrary file upload vulnerability in BigAnt Server 2.97 SP7. A lack of authentication allows to make unauthenticated file uploads through a DUPF command. Additionally the filename option in the same command can be used to launch a directory traversal attack and achieve arbitrary file upload. The module uses uses the Windows Management Instrumentation service to execute an arbitrary payload on vulnerable installations of BigAnt on Windows XP and 2003. It has been successfully tested on BigAnt Server 2.97 SP7 over Windows XP SP3 and 2003 SP2.

tags | exploit, arbitrary, file upload
systems | windows
advisories | CVE-2012-6274, OSVDB-89342
SHA-256 | dc87880460e34e43169ec0e0613b958641d3dd6f47c0902d800d64b756f31d6e
OpenEMR PHP File Upload
Posted Feb 20, 2013
Authored by LiquidWorm, juan vazquez | Site metasploit.com

This Metasploit module exploits a vulnerability found in OpenEMR 4.1.1. By abusing the ofc_upload_image.php file from the openflashchart library, a malicious user can upload a file to the tmp-upload-images directory without any authentication, which results in arbitrary code execution. The module has been tested successfully on OpenEMR 4.1.1 over Ubuntu 10.04.

tags | exploit, arbitrary, php, code execution
systems | linux, ubuntu
advisories | OSVDB-90222
SHA-256 | 09f5efca41c484db706376ef3dfea164467c56c4d486e5b9040b98c0af8c332a
Squirrelcart 3.5.4 Cross Site Scripting
Posted Feb 20, 2013
Authored by LiquidWorm | Site zeroscience.mk

Squirrelcart version 3.5.4 suffers from a reflective cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a46543a8bb0ab278d3990bfe150c544ddc8dd309411ee1a9c232ac64cf315571
Various Applications Include ZeroClipboard XSS
Posted Feb 20, 2013
Authored by MustLive

YAML, MultiProject extension for Trac, UserCollections extension for Piwigo, TAO and TableTools plugin for DataTables plugin for jQuery are all affected by the cross site scripting issues discovered in ZeroClipboard as they include the swf.

tags | exploit, xss
SHA-256 | d81a83c614cfc84ec66ca68b939dab7074dc98d401693f0c5c6943182dcd0229
Kodak Insite Creative Workflow System SQL Injection
Posted Feb 19, 2013
Authored by Robert at Hipcrime

Kodak's Insite Creative Workflow System suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | dfd8885731a743f54a2b98717b42b9119da28cb80197e4c3bcd619044a40a31f
MyFi Wireless Disk 1.2 CSRF / LFI / Code Execution
Posted Feb 19, 2013
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

MyFi Wireless Disk version 1.2 suffers from cross site request forgery, local file inclusion, and remote command injection vulnerabilities.

tags | exploit, remote, local, vulnerability, file inclusion, csrf
SHA-256 | 6ed86f1279f3c02e7df43034482ff6bf89be0c4ffd9b21dc08e458c3678096fe
Page 2 of 7
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close