what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 242 RSS Feed

Files

Chamilo LMS Cross Site Scripting
Posted Feb 19, 2016
Authored by Vulnerability Laboratory, Lawrence Amer | Site vulnerability-lab.com

Chamilo LMS suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | bc13f65de0792bdc1e2bb9fd29ab0d6fdffa9843148374f7b6d135c76354780c
Chamilo LMS Insecure Direct Object Reference
Posted Feb 19, 2016
Authored by Vulnerability Laboratory, Lawrence Amer | Site vulnerability-lab.com

Chamilo LMS suffers from an insecure direct object reference vulnerability.

tags | exploit
SHA-256 | 45ca288b13f7415dfb28d2c6c6aa16e6f8a5baf6d21c4e8d7a1a099587d9f341
Investors Application Cross Site Scripting
Posted Feb 19, 2016
Authored by Hadji Samir, Vulnerability Laboratory | Site vulnerability-lab.com

Investors Application suffered from a client-side script insertion vulnerability.

tags | exploit
SHA-256 | 31b0a0b759a2c2c22be39be00d0d6a5f2c966fb77f6eb6b664a25e861da3f5e3
Prezi Cross Site Scripting / Open Redirect
Posted Feb 19, 2016
Authored by Vulnerability Laboratory, Milan A Solanki | Site vulnerability-lab.com

Prezi suffered from cross site scripting and open redirection vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | a9272aa1383aa28eef7ba0439aca2188d07e11e69f869dfc892626f1450eac10
iFixIt Profile Cross Site Scripting
Posted Feb 19, 2016
Authored by Hadji Samir, Vulnerability Laboratory | Site vulnerability-lab.com

iFixIt suffered from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 61832184f77e03ab41094e0f543daad18e092a25bb0e0f4885e0fa9dbb5d593a
iFixIt Guide Cross Site Scripting
Posted Feb 19, 2016
Authored by Hadji Samir, Vulnerability Laboratory | Site vulnerability-lab.com

iFixIt suffered from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 298e8300b75f167cea651ce178b15c762d1853e337ce965c048f7d2cfd7f991b
STIMS Cutter 1.1.3.20 SEH Overwrite Buffer Overflow
Posted Feb 19, 2016
Authored by Shantanu Khandelwal

STIMS Cutter version 1.1.3.20 overflow proof of concept with SEH overwrite.

tags | exploit, overflow, proof of concept
SHA-256 | 7630dfcf1c23685d5ff746caef2a3193e9af63121e6307de11d7b6a33841ebc0
DirectAdmin 1.491 Cross Site Request Forgery
Posted Feb 18, 2016
Authored by Necmettin COSKUN

DirectAdmin version 1.491 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 46c874ed2505a5df8e83a213d020c5a1bde6cce21994c9b4f390cc5cf69c4532
WeBid 1.1.2P2 SQL Injection
Posted Feb 18, 2016
Authored by High-Tech Bridge SA | Site htbridge.com

WeBid version 1.1.2P2 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 4c445d18ff897468b32229c61b93169d17ee6ba88ec405da9f786b7a7906b6fd
webSPELL 4.2.4 Cross Site Request Forgery / SQL Injection
Posted Feb 18, 2016
Authored by High-Tech Bridge SA | Site htbridge.com

webSPELL version 4.2.4 suffers from cross site request forgery and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, csrf
SHA-256 | 2291468cde58eae41054890b9e25d4217654ae9d0f8b7b9e749e1192bdcd7e44
DOKEOS ce30 Authentication Bypass
Posted Feb 18, 2016
Authored by High-Tech Bridge SA | Site htbridge.com

DOKEOS version ce30 suffers from an authentication bypass vulnerability.

tags | exploit, bypass
SHA-256 | e0d80f4d11e0f37a08bd45c5adf3616f68bc949b8f350966e67ed9a9b99c6a86
TestLink 1.9.14 SQL Injection
Posted Feb 18, 2016
Authored by High-Tech Bridge SA | Site htbridge.com

TestLink version 1.9.14 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 91d1c80956419cb3834dcfcd444983fe9cb7d79deae450a0f99e91da4a1bf961
Osclass 3.5.9 SQL Injection
Posted Feb 18, 2016
Authored by High-Tech Bridge SA | Site htbridge.com

Osclass version 3.5.9 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 1873a8e1196208b1b465380f46ad84e72520251b671aaa4c7dd577b9cff925a1
osCmax 2.5.4 Code Execution / CSRF / Local File Inclusion
Posted Feb 18, 2016
Authored by High-Tech Bridge SA | Site htbridge.com

osCmax version 2.5.4 suffers from code execution, cross site request forgery, and local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, code execution, file inclusion, csrf
SHA-256 | 4ad8190811bf2819eca13b86515ec3b6f35acf38818dc02e5c40e799d449f463
osCommerce 2.3.4 Local File Inclusion / Cross Site Request Forgery
Posted Feb 18, 2016
Authored by High-Tech Bridge SA | Site htbridge.com

osCommerce version 2.3.4 suffers from cross site request forgery and local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, file inclusion, csrf
SHA-256 | 0590c4c85647c5c0a02e877aee9bff53f2ee293542d8d20f50cdb9048d52be0f
Comodo Internet Security VNC Server Exposure
Posted Feb 18, 2016
Authored by Tavis Ormandy, Google Security Research

Comodo Internet Security installs GeekBuddy which installs a weakly secure exposed VNC server.

tags | exploit
systems | linux
advisories | CVE-2014-7872
SHA-256 | 3d2e073c1d6d171f88727d9420abce1904c883acad79c0452fffab5ce7a41451
Umbraco SSRF / Cross Site Request Forgery / Cross Site Scripting
Posted Feb 18, 2016
Authored by Sandeep Kamble

Umbraco versions prior to 7.4.0 suffers from server-side request forgery, cross site request forgery, and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 20bc965b21baa931f940d7ed6d8a9e9f44777aeb1ea263df14aa21c1cf9f5104
Vesta Control Panel 0.9.8-15 Cross Site Scripting
Posted Feb 18, 2016
Authored by Necmettin COSKUN

Vesta Control Panel versions 0.9.8-15 and below suffer from a persistent cross site scripting vulnerability via the user agent.

tags | exploit, xss
SHA-256 | d430afd4621b5d62dad4b70ffff8d6258610f314f51abde198f22b3b9841fd8d
Ebay Cross Site Scripting
Posted Feb 18, 2016
Authored by Alexander Korznikov

ebay.com suffered from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a29879e61b3488fdba8438c12dd745e034bbd5c2a76b31866e02d794bf818ecd
Cisco ASA VPN Portal Cross Site Scripting
Posted Feb 17, 2016
Authored by Juan Sacco

The Cisco ASA VPN Portal password recovery page suffers from a cross site scripting vulnerability.

tags | exploit, xss
systems | cisco
SHA-256 | eb2aac6086f4bb061f2a2742410500a3e2ba73666fb36027d37e43f8e424ecfc
Adobe Flash TextField Constructor Type Confusion
Posted Feb 17, 2016
Authored by Google Security Research, natashenka

There is a type confusion vulnerability in the TextField constructor in AS3. When a TextField is constructed, a generic backing object is created and reused when subsequent TextField objects are created. However, if an object with the same ID has already been created in the SWF, it can be of the wrong type. The constructor contains a check for this situation, though, and throws an exception and sets a flag to shut down the player if this occurs. The backing object is then set to be of type TextField to avoid any modifications that have been made on it by the constructor from causing problems if it is used as an object of its original type elsewhere in the player. However, if the exception thrown by the constructor is caught, the exception handler can create another TextField object, and since the type of the generic backing object has been changed, an object of the wrong type is now backing the TextField, which makes it possible to set the pointers in the object to integer values selected by the attacker. The PoC swf for this issue needs to be created by hand.

tags | exploit
systems | linux
advisories | CVE-2016-0985
SHA-256 | 89244b28a4549217c3946663d62b8133ad186a92cdb4285eeff70e6a18cdb172
Adobe Flash Sound.loadPCMFromByteArray Dangling Pointer
Posted Feb 17, 2016
Authored by Google Security Research, natashenka

There is a dangling pointer that can be read, but not written to in loadPCMFromByteArray. A proof of concept is included.

tags | exploit, proof of concept
systems | linux
advisories | CVE-2016-0984
SHA-256 | 6a837aeb0f69779cabe3ac91d53929ecab287b6e562f832a1364d2e7e1364980
Adobe Flash LoadVars.decode Use-After-Free
Posted Feb 17, 2016
Authored by Google Security Research, natashenka

There is a use-after-free in LoadVars.decode. If a watch is set on the object that the parameters are being decoded into, and the watch deletes the object, then other methods are called on the deleted object after it is freed.

tags | exploit
systems | linux
advisories | CVE-2016-0974
SHA-256 | fbe2ae5d15b3901564ae333ef65dc05ba1b8f150b143e8b0a87296c853c3503a
Adobe Flash ATF Processing Heap Overflow
Posted Feb 17, 2016
Authored by Google Security Research, mjurczyk

The included file causes a crash due to a heap overflow, probably due to an issue in ATF processing by the URLStream class.

tags | exploit, overflow
systems | linux
advisories | CVE-2016-0971
SHA-256 | 31320a678e0ba948912307dabf47b9cca5c8ea878f23514c24959ad680fe11f2
Adobe Flash H264 File Causes Stack Corruption
Posted Feb 17, 2016
Authored by Google Security Research, mjurczyk

The included flv file causes stack corruption when loaded into Flash. To use the PoC, load LoadMP42.swf?file=lownull.flv from a remote server.

tags | exploit, remote
systems | linux
advisories | CVE-2016-0967
SHA-256 | 74d667d649a7d045b24409e6c7c68eeea9f6f1cc6f03497a67ed1756ff630172
Page 4 of 10
Back23456Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Google Patches Critical Chrome Vulnerability
Posted Apr 24, 2024

tags | headline, flaw, google, patch, chrome
Hackers Are Using Developing Countries For Ransomware Practice
Posted Apr 24, 2024

tags | headline, hacker, malware, cybercrime, fraud, cryptography
Authorities Investigate LabHost Users After Phishing Service Shutdown
Posted Apr 23, 2024

tags | headline, cybercrime, fraud, phish
Windows Vulnerability Reported By The NSA Exploited To Install Russian Malware
Posted Apr 23, 2024

tags | headline, government, microsoft, usa, russia, flaw, cyberwar, spyware, nsa
UnitedHealth Admits Breach Could Cover Substantial Proportion Of People In America
Posted Apr 23, 2024

tags | headline, hacker, privacy, data loss
Microsoft DRM Hack Could Allow Movie Downloads From Streaming
Posted Apr 23, 2024

tags | headline, microsoft, flaw, pirate
Over A Million Neighbourhood Watch Members Exposed
Posted Apr 23, 2024

tags | headline, privacy, britain, data loss
MITRE Hacked By State Sponsored Group Via Ivanti Zero Days
Posted Apr 23, 2024

tags | headline, hacker, government
Russia's Sandworm APT Linked To Attack On Texas Water Plant
Posted Apr 18, 2024

tags | headline, malware, usa, russia, cyberwar, scada
EU Tells Meta It Can't Paywall Privacy
Posted Apr 18, 2024

tags | headline, government, privacy, facebook, social
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close