what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 127 RSS Feed

Files

Packet Storm New Exploits For May, 2013
Posted Jun 2, 2013
Authored by Todd J. | Site packetstormsecurity.com

This archive contains all of the 126 exploits added to Packet Storm in May, 2013.

tags | exploit
systems | linux
SHA-256 | c29831f658ed77c2534eddffe84f7ab2fbc633835a65c57ff018013e6ceac702
Lianja SQL 1.0.0RC5.1 db_netserver Stack Buffer Overflow
Posted May 31, 2013
Authored by Spencer McIntyre | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in the db_netserver process which is spawned by the Lianja SQL server. The issue is fixed in Lianja SQL 1.0.0RC5.2.

tags | exploit, overflow
advisories | CVE-2013-3563
SHA-256 | 7e06bdae955716ffa265faef6d8a8657fd4b8897f76d0c56b6eba227f9c8cabd
Logic Print 2013 Stack Overflow
Posted May 30, 2013
Authored by h1ch4m

Logic Print 2013 suffers from a stack overflow vulnerability.

tags | exploit, overflow
SHA-256 | ba1216bc16af7f8d80b5c358f6e4541518b85fb4b8d3fc8150c331d6f1c6e2a1
Intrasrv Simple Web Server 1.0 Code Execution
Posted May 30, 2013
Authored by xis_one

Intrasrv Simple Web Server version 1.0 SEH based remote code execution exploit.

tags | exploit, remote, web, code execution
SHA-256 | 912fd073e0d783dd318697693b042acb7b403d1ca339837fcfa75c842e5512b8
ModSecurity Remote Null Pointer Dereference
Posted May 29, 2013
Authored by Younes JAAIDI

When ModSecurity receives a request body with a size bigger than the value set by the "SecRequestBodyInMemoryLimit" and with a "Content-Type" that has no request body processor mapped to it, ModSecurity will systematically crash on every call to "forceRequestBodyVariable" (in phase 1). This is the proof of concept exploit. Versions prior to 2.7.4 are affected.

tags | exploit, proof of concept
advisories | CVE-2013-2765
SHA-256 | b4e14816e4c5cdc0de651f2cc750a97fa531e3a0c488cb71922a3bc534259845
Monkey HTTPD 1.1.1 Denial Of Service
Posted May 29, 2013
Authored by dougtko

Monkey HTTPD version 1.1.1 suffers from a denial of service vulnerability.

tags | exploit, denial of service
advisories | CVE-2013-3724
SHA-256 | 9f43c0d9a2bd9b380f9c63f0e17d6265c76af43e959168f66ca0eb9c22f6dac0
YeaLink IP Phone Firmware 9.70.0.100 Missing Authentication
Posted May 29, 2013
Authored by b0hr

YeaLink IP Phone firmware versions 9.70.0.100 and below suffer from an unauthenticated phone call vulnerability.

tags | exploit, bypass
SHA-256 | 22671d10a80df232f64150e4e78af6be36a8803fbdb6475a8eb01087172a3425
TP-LINK WR842ND Directory Traversal
Posted May 29, 2013
Authored by Adam Simuntis

TP-LINK WR842ND suffers from a remote directory traversal vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | ac4197fdb577b1dab807bec29d445b9cd6d5ff28f301aaac5ea7915033dfc735
TP-Link IP Camera Hardcoded Credentials / Command Injection
Posted May 28, 2013
Authored by Core Security Technologies, Nahuel Riva, Francisco Falcon | Site coresecurity.com

TP-Link IP cameras suffer from hard-coded credential and remote command execution vulnerabilities.

tags | exploit, remote, vulnerability
advisories | CVE-2013-2573, CVE-2013-2572
SHA-256 | d96b583866927f2f59a08545c251d956a2dfef2c6512197cefb588c1ac39997b
SIEMENS Solid Edge ST4 SEListCtrlX Code Execution
Posted May 28, 2013
Authored by rgod | Site retrogod.altervista.org

SIEMENS Solid Edge ST4 SEListCtrlX active-x control SetItemReadOnly suffers from an arbitrary memory rewrite remote code execution vulnerability. Proof of concept included.

tags | exploit, remote, arbitrary, code execution, activex, proof of concept
systems | linux
SHA-256 | 6c6ea1a9c072ee2af175d48c30c8a9025b2eddad5dddcf7ee400ddb53f111796
MayGion IP Camera Path Traversal / Buffer Overflow
Posted May 28, 2013
Authored by Core Security Technologies | Site coresecurity.com

Core Security Technologies Advisory - MayGion IP cameras suffer from path traversal and buffer overflow vulnerabilities.

tags | exploit, overflow, vulnerability
advisories | CVE-2013-1604, CVE-2013-1605
SHA-256 | 21e644d9151837b4ab263d654102bff96b1ab9d864c49f37c40e5bb8d1affef9
IBM SPSS SamplePower C1Tab ActiveX Heap Overflow
Posted May 28, 2013
Authored by Alexander Gavrun, juan vazquez | Site metasploit.com

This Metasploit module exploits a heap based buffer overflow in the C1Tab ActiveX control, while handling the TabCaption property. The affected control can be found in the c1sizer.ocx component as included with IBM SPSS SamplePower 3.0. This Metasploit module has been tested successfully on IE 6, 7 and 8 on Windows XP SP3 and IE 8 on Windows 7 SP1.

tags | exploit, overflow, activex
systems | windows
advisories | CVE-2012-5946, OSVDB-92845
SHA-256 | 99fdd7d6b7ffc3bcb3ad029cfcdb362a9cb2e0bb387ffdddfabe715b79e167a0
Barracuda SSL VPN 680 2.2.2.203 Open Redirect
Posted May 28, 2013
Authored by Chokri Ben Achor, Dave Farrow, Vulnerability Laboratory | Site vulnerability-lab.com

Barracuda SSL VPN 680 2.2.2.203 suffers from an open redirection vulnerability.

tags | exploit
SHA-256 | 5740b1e5e5c9fc656d5fb5cfcb35cf011fa06b52f64e6aab8dc7973c32b15373
Zavio IP Camera Command Injection / Bypass
Posted May 28, 2013
Authored by Core Security Technologies, Nahuel Riva, Francisco Falcon | Site coresecurity.com

Core Security Technologies Advisory - Zavio IP cameras based on firmware versions 1.6.03 and below suffer from bypass, hard-coded credential, and arbitrary command execution vulnerabilities.

tags | exploit, arbitrary, vulnerability
advisories | CVE-2013-2567, CVE-2013-2568, CVE-2013-2569, CVE-2013-2570
SHA-256 | 78c356b2ffcb1e25d51e6592b9d5d73b842cdf1d53ab057c2850cde52d3c84c9
PayPal France SQL Injection
Posted May 28, 2013
Authored by Karim H.B., Vulnerability Laboratory | Site vulnerability-lab.com

PayPal's France site suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | d909644459dddf2b6cbe04e3ffd37a2c6cbdcb1c02e0db96d8b6c8ea94d96274
PayPal Cross Site Scripting
Posted May 28, 2013
Authored by Un0wn_X

The sitewide search functionality in PayPal suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ae6f81d653037a6970d54135bf3aa3926b4d02177b5fea9343cd38d0f832748a
HP LaserJet Pro P1606dn Password Reset
Posted May 28, 2013
Authored by m3tamantra

HP LaserJet Pro version P1606dn suffers from a direct access administrative password reset vulnerability.

tags | exploit
SHA-256 | 1e0546a1b6c0fd44f287a4018259a51dd668ffc155e34387e618de9957eea8a8
SIEMENS Solid Edge ST4 WebPartHelper Command Execution
Posted May 27, 2013
Authored by rgod | Site retrogod.altervista.org

SIEMENS Solid Edge ST4 WebPartHelper active-x control RFMSsvs!JShellExecuteEx suffers from a remote command execution vulnerability. Proof of concept included.

tags | exploit, remote, activex, proof of concept
systems | linux
SHA-256 | bba4a31d339af5605fe114b27057d1acf37770767071972f2e917ba1e3684b20
aCMS 1.0 XSS / Content Spoofing / Information Leak
Posted May 27, 2013
Authored by MustLive

aCMS versions 1.0 and below suffer from cross site scripting, content spoofing, and information leakage vulnerabilities.

tags | exploit, spoof, vulnerability, xss
SHA-256 | ae8043acb7b2da9c98837d31f51c47bde25e8182d74dffb82eb080368936bda9
WordPress User Role Editor 3.12 Cross Site Request Forgery
Posted May 27, 2013
Authored by Henry Hoggard

WordPress User Role Editor plugin version 3.12 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | f881320e4a6513457ac1d19645502215a0dc771eccc30dd7bd787ce5cc531b2e
ADIF Log Search Widget 1.0e Cross Site Scripting
Posted May 27, 2013
Authored by Keith Makan

ADIF Log Search Widget version 1.0e suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | bf0e8effce0aa1d22148afab86ac617ac9aa5103faece658ec9c15fcadf7e673
Vanilla Forums 2.0.18.8 XSS / Insecure Permissions
Posted May 27, 2013
Authored by Henry Hoggard

Vanilla Forums version 2.0.18.8 suffers from cross site scripting and insecure permission vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | cc1d87f0dc1b0be146646d781abad9170ec4421ef9d3f355fdde9a8d86df9705
LG Optimus G Command Injection
Posted May 26, 2013
Authored by Justin Case

LG Optimus G E973 suffers from a command injection vulnerability.

tags | exploit
advisories | CVE-2013-3666
SHA-256 | 52c14a7776a3df48b367725a4f0a4d5cea76882a924fd60859316427d1ef5748
PayPal.com Cross Site Scripting
Posted May 26, 2013
Authored by Robert Kugler

PayPal.com suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | c455574d672149e36625a44552fd8f9de3058a5512e438e175b6cb80fb8c2282
SAS Integration Technologies Client 9.31_M1 Buffer Overflow
Posted May 25, 2013
Authored by LiquidWorm | Site zeroscience.mk

The SASspk module (SASspk.dll) version 9.310.0.11307, has a function called 'RetrieveBinaryFile()' which has one parameter called 'bstrFileName' which takes arguments as strings as defined in the function itself as ISPKBinaryFile from the SASPackageRetrieve library. Stack-based buffer overflow was discovered in one of the fuzzing processes that could allow arbitrary code execution by an attacker when exploiting the non-sanitized 'bstrFileName' parameter.

tags | exploit, overflow, arbitrary, code execution
systems | windows
SHA-256 | 520def5ba164f9a7f1d632ee1f23ece85df9bc7454425ba51968438158fe9eda
Page 1 of 6
Back12345Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close