exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 165 RSS Feed

Files

Rebus:list SQL Injection
Posted Mar 18, 2013
Authored by Robert Cooper

Rebus:list suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 346eae0666cf8b6d57c06d6863f4273a4dc4aad8a7f734a187ea2a43318b2d8a
Joomla RSfiles SQL Injection
Posted Mar 18, 2013
Authored by ByEge

The Joomla RSfiles component suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 878f37ba2d41f24faeb5ec2926a1b3e8e8e8dae83c8e76e91355b9fa3d139ead
WordPress Simply Poll 1.4.1 CSRF / XSS
Posted Mar 18, 2013
Authored by m3tamantra

WordPress Simply Poll third party plugin version 1.4.1 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | ddddad68953e748aca3717d171b456e43176604fc0cffd022c7d37a8ba52922e
Sami FTP Server 2.0.1 PUT Command Buffer Overflow
Posted Mar 18, 2013
Authored by ne0z

Sami FTP server version 2.0.1 PUT command buffer overflow exploit with DEP bypass. Written in Python.

tags | exploit, overflow, python
SHA-256 | 8159a50021210d0417c9c4dfb1db9a6b41e41225e88e15e69485e9a6794eb4d2
Scripteen FunPhoto Mix Cross Site Scripting
Posted Mar 18, 2013
Authored by 3spi0n

Scripteen FunPhoto Mix suffers form a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | e8c7ce5534c56e058f80854b0ef2e32456a54d16c50b0b3203dd20fef2710264
Polycom H.323 Format String
Posted Mar 15, 2013
Authored by Moritz Jodeit | Site nruns.com

Polycom systems suffer from a format string vulnerability when creating a CDR entry. Polycom HDX series versions prior to 3.1.1.2 are affected.

tags | exploit
SHA-256 | 8998433b0bea32dde00acd6d3311c61443b062424f5faeac20c6cdfee2adbe3b
Polycom H.323 CDR Database SQL Injection
Posted Mar 15, 2013
Authored by Moritz Jodeit | Site nruns.com

A simple H.323 SETUP packet can be used to commit a remote SQL injection attack against Polycom systems. Polycom HDX series versions prior to 3.1.1.2 are affected.

tags | exploit, remote, sql injection
SHA-256 | c8ef16e32d79b56646936f40819360d5231808c030efb457b8afed16f3c94923
Polycom Firmware Update Command Injection
Posted Mar 15, 2013
Authored by Moritz Jodeit | Site nruns.com

The firmware update functionality in the Polycom web interface is vulnerable to a simple command injection vulnerability which allows an attacker with access to the web interface to execute arbitrary commands on the underlying embedded Linux system. Polycom HDX series versions prior to 3.1.1.2 are affected.

tags | exploit, web, arbitrary
systems | linux
SHA-256 | eaeed66e6e35211d5de8494085612d6cabc696df21d84244931e4cb825cb4492
DaloRadius CSRF / XSS / SQL Injection
Posted Mar 15, 2013
Authored by Saadat Ullah

DaloRadius suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection, csrf
SHA-256 | dac44b7efab3b59bb2bece48236156df6cdf384dff8f1629a610c458be0fe847
Skype Click To Call 6.2.0.106 Privilege Escalation
Posted Mar 15, 2013
Authored by otr

The default installation of Skype is vulnerable to a local privilege escalation attack that allows an unprivileged attacker to execute arbitrary code with NT AUTHORITY/SYSTEM privileges. Versions 6.2.0.106 and below are affected.

tags | exploit, arbitrary, local
SHA-256 | d220809c5a2ec3bca6b7d83539650b12420bc8778406212fc05cd585e28a6a0f
Polycom HDX Privilege Escalation
Posted Mar 15, 2013
Authored by Moritz Jodeit | Site nruns.com

The Polycom Command Shell can be used to view and also change several settings of the system. However it can also be used to get system-level access (i.e. root access) to the HDX system. The "printenv" and "setenv" commands can be used to read and write variables respectively which are stored in flash memory. Polycom HDX series versions prior to 3.1.1.2 are affected.

tags | exploit, shell, root
SHA-256 | 162aad6a25e60bab68f51ec49f90cbda2650407c9f0ac15d752cc71dba4606be
OpenPLI Webif Arbitrary Command Execution
Posted Mar 15, 2013
Authored by Michael Messner | Site metasploit.com

Some Dream Boxes with OpenPLI version 3 beta images are vulnerable to OS command injection in the Webif 6.0.4 web interface. This is a blind injection, which means that you will not see any output of your command. A ping command can be used for testing the vulnerability. This Metasploit module has been tested in a box with the next features: Linux Kernel version 2.6.9 (build@plibouwserver) (gcc version 3.4.4) #1 Wed Aug 17 23:54:07 CEST 2011, Firmware release 1.1.0 (27.01.2013), FP Firmware 1.06 and Web Interface 6.0.4-Expert (PLi edition).

tags | exploit, web, kernel
systems | linux
advisories | OSVDB-90230
SHA-256 | 08146370ff7e87193e0ac650501ba578d139728fdb5da79083867c3d68983b6c
WordPress LeagueManager 3.8 SQL Injection
Posted Mar 15, 2013
Authored by Joshua Reynolds | Site infosec4breakfast.com

WordPress LeagueManager plugin version 3.8 suffers from a remote SQL injection vulnerability. Both an exploit along with patching recommendations are provided.

tags | exploit, remote, sql injection
advisories | CVE-2013-1852
SHA-256 | a3e13cf6b95a3336ab25ac8195f16b3844e2f53413a7db2fbea7d99a9a980665
Petite Annonce 1 Cross Site Scripting
Posted Mar 15, 2013
Authored by Metropolis

Petite Annonce version 1 suffers from a cross site scripting vulnerability in moteur-prix.php.

tags | exploit, php, xss
SHA-256 | 4d7c27491eec42b373a976e3e8c93b8036534ebe80480c62b3a9c04bc029abf3
Google Chrome 21.0.1180.57 NULL Pointer
Posted Mar 14, 2013
Authored by Heyder Andrade

Google Chrome versions 21.0.1180.57 and below suffer from a NULL pointer vulnerability in InspectDataSource::StartDataRequest.

tags | exploit
SHA-256 | 922f2c1e74a32dc38ee0d67c6334a31517da282683a2f06192b0fea1c6e5da62
QuinStreet Database ID Spoofing
Posted Mar 14, 2013
Authored by Henry Garrison

A confirmed security vulnerability has been identified with 30 high traffic web sites owned by QuinStreet. The vendor stores database IDs in cookies which are easily spoofed (USERID_COOKIE), allowing all user information to be accessed.

tags | exploit, web, spoof
SHA-256 | 12c6c5deb30c5b87678c3f751877699e042013d41da09a3c32d7c0543db5a1a8
nCircle IP360 7.0 LDAP Password Disclosure
Posted Mar 14, 2013
Authored by havesome0day

nCircle IP360 version 7.0 discloses the LDAP password in cleartext in their HTML code.

tags | exploit
SHA-256 | 65936fc21494ca5ba065730abc8ffc017c2866821962e6b47e4b86851827acdf
ClipShare 4.1.4 SQL Injection / Plaintext Password
Posted Mar 14, 2013
Authored by Akastep

ClipShare version 4.1.4 suffers from remote blind SQL injection and plaintext password vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | a568735b6f3205c221aee116bd737215c0b537dd6bb646bc342ef61168392866
Cisco Video Surveillance Operations Manager 6.3.2 XSS / LFI / Bypass
Posted Mar 14, 2013
Authored by Bassem

Cisco Video Surveillance Operations Manager version 6.3.2 suffers from cross site scripting, access bypass, and local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, xss, bypass, file inclusion
systems | cisco
SHA-256 | 889a7c95fe9ba307b4476548a140238036f8459886d5305efa04819e7fdd2104
Open-Xchange 6 XSS / LFI / SSRF / Hashing
Posted Mar 14, 2013
Authored by Martin Braun

Open-Xchange version 6 suffers from cross site scripting, local file inclusion, HTTP header injection / response splitting, missing SSL enforcement, server-side request forging, insecure password hashing, and file permission vulnerabilities.

tags | exploit, web, local, vulnerability, xss, file inclusion
advisories | CVE-2013-1645, CVE-2013-1646, CVE-2013-1647, CVE-2013-1648, CVE-2013-1649, CVE-2013-1650, CVE-2013-1651
SHA-256 | 8be9974c5b91f42a1ca77eb417301430aea4147dc0179c425ee43fbe9ef5c36e
Fedora Linux SOCK_DIAG Local Root
Posted Mar 13, 2013
Authored by Thiebaud Weksteen

Local root exploit for Fedora 18 x86_64 using nl_table to leverage the sock_diag_handlers[] vulnerability.

tags | exploit, local, root
systems | linux, fedora
advisories | CVE-2013-1763
SHA-256 | 1ab629c5ad74a701d6a87ea1e2c30d5f307d18d3171c1f44adb7736878b5c4ba
Linux Kernel SCTP_GET_ASSOC_STATS() Buffer Overflow
Posted Mar 13, 2013
Authored by Petr Matousek

Proof of concept code that demonstrates a stack-based buffer overflow in the Linux kernel SCTP_GET_ASSOC_STATS() function.

tags | exploit, overflow, kernel, proof of concept
systems | linux
advisories | CVE-2013-1828
SHA-256 | 588169341383534eb48214aef23de1ecd3b8f43f820fc7090163879acbcb9dc3
Ruby Gem Curl Command Execution
Posted Mar 13, 2013
Authored by Larry W. Cashdollar

Ruby Gem Curl suffers from a remote command execution vulnerability due to a lack of user input sanitization.

tags | exploit, remote, ruby
SHA-256 | c96fc864359b4f3b2f30998551d780075c8307fbf1c24791422f696b650146ef
Ruby Gem Minimagic Command Execution
Posted Mar 13, 2013
Authored by Larry W. Cashdollar

Ruby Gem MiniMagic suffers from a remote command execution vulnerability due to a lack of user input sanitization.

tags | exploit, remote, code execution, ruby
SHA-256 | f3b4827a94b047303ccc02b88c3f74c2860bb4df87e899281dfb759760495123
Ruby Gem Fastreader 1.0.8 Command Execution
Posted Mar 13, 2013
Authored by Larry W. Cashdollar

Ruby Gem Fastreader version 1.0.8 suffers from a remote command execution vulnerability due to a lack of user input sanitization.

tags | exploit, remote, code execution, ruby
SHA-256 | 1fab775f0aafbbbde6c3e31e5072977d382d54542fa209d3fc109a74349d293a
Page 4 of 7
Back23456Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close