what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 28 RSS Feed

Files from Juan Carlos Garcia

First Active2013-01-13
Last Active2014-05-30
ProtonMail.ch Header Injection / CSRF
Posted May 30, 2014
Authored by Juan Carlos Garcia, Francisco Moraga

ProtonMail.ch suffers from cross site request forgery, header injection, and out of date software vulnerabilities. Note that this finding houses site-specific data.

tags | exploit, vulnerability, csrf
SHA-256 | 3d088ba11847cc70c4f57d4cfaf4266199b8c8da68a1d4fbf240d3513b40af99
AOL File Inclusion / Cross Site Scripting
Posted Jan 22, 2014
Authored by Juan Carlos Garcia

America Online (AOL) suffers from cross site scripting and remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, code execution, xss, file inclusion
SHA-256 | 8a613994798545bcea472db93af4ceb0b66319269963bcb88f660250d728a92b
Ring Jordan SQL Injection
Posted Dec 13, 2013
Authored by Juan Carlos Garcia

Ring Jordan suffers from a remote SQL injection vulnerability in their administrative functionality. The author has tried to contact the vendor and has received no response. The SQL injection issue allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | b0303595796d9f5fd9fd11582864f2c0b8d4f8b08600a13e9711b7fbd093fa52
Vatican Web Site Cross Site Scripting
Posted Dec 12, 2013
Authored by Juan Carlos Garcia

The official Vatican web site suffers from a cross site scripting vulnerability.

tags | exploit, web, xss
SHA-256 | d803f05012af0c7d4a8ad518230fd5aa68d9934addc4f1e0ac0b93fd249f5c2c
NOAA.gov XSS / CSRF / Clickjacking
Posted Nov 24, 2013
Authored by Juan Carlos Garcia

NOAA.gov suffers from cross site request forgery, cross site scripting, and clickjacking vulnerabilities. The authored has tried to contact them but has received no response.

tags | advisory, vulnerability, xss, csrf
SHA-256 | c1f55ea29ba7cf55838a8a216d2e5c0918b27490eb78e8f438416ea546ac11c2
Kartoo Search Engine XSS / Remote File Inclusion
Posted Nov 19, 2013
Authored by Juan Carlos Garcia

Kartoo Search Engine suffers from information disclosure, cross site scripting, and remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, code execution, xss, file inclusion, info disclosure
SHA-256 | ac0a06fa419a184ad1babb025e7077989ed37dedb335c4eb2588feb10cb78804
Optomise System Ltd XSS / Information Disclosure
Posted Nov 18, 2013
Authored by Juan Carlos Garcia

Optomise System Ltd suffers from cross site scripting and information disclosure vulnerabilities.

tags | exploit, vulnerability, xss, info disclosure
SHA-256 | c1f0ce5a3fe26ddb99b0616d5d61b0460e2f1e5b210f0a665619a91d61d91148
Adaudit Plus Online Demo CSRF / Poor Password Passing
Posted Oct 18, 2013
Authored by Juan Carlos Garcia

Adaudit Plus Online Demo suffers from multiple vulnerabilities including cross site request forgery, directory listing, and passwords being passed via a GET method.

tags | exploit, vulnerability, csrf
SHA-256 | 65032b7037f6db49f90a134d34c24c4a670cbee2a380df40c787cac1f3f32132
Admanager Plus Online Demo XSS / CSRF / Clickjacking
Posted Oct 18, 2013
Authored by Juan Carlos Garcia

Admanager Plus Online Demo suffers from cross site request forgery, directory listing, clickjacking, and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | ef8980f8307fd85e258505ff90f13dbeb382094a1fe35e49f7d82febddc5223e
Pagelime CMS XSS / Credential Disclosure
Posted Oct 14, 2013
Authored by Juan Carlos Garcia

Pagelime CMS suffers from cross site scripting, unencrypted __VIEWSTATE parameter, credentials being sent in the clear, and various other security issues.

tags | exploit, xss
SHA-256 | a438a73e380380d700a8be6d0a80415637a312aaaf38398234e40b95d0a106f7
Opolis.eu Secure Mail Blind SQL Injection / XSS / CSRF / DoS
Posted Oct 7, 2013
Authored by Juan Carlos Garcia

Opolis.eu suffers from cross site request forgery, cross site scripting, denial of service, and remote blind SQL injection vulnerabilities. The vendor has not responded to the researchers reports of these issues.

tags | exploit, remote, denial of service, vulnerability, xss, sql injection, info disclosure, csrf
SHA-256 | 86e6756e6360245c7ec7594467c4b1d5869733852ffe83875227e09f6118918a
S-Mail.com PHP / Apache Issues
Posted Oct 7, 2013
Authored by Juan Carlos Garcia

Secure Mail at s-mail.com actually suffers from dozens of vulnerabilities due to using out of date PHP and Apache versions.

tags | advisory, php, vulnerability
SHA-256 | bcf4a8a35493dc589f526c3acdfdd2b8596c418c332e7d75666242af1c71a388
UniCredit Bank Cross Site Request Forgery / Cross Site Scripting / Shell Upload
Posted Oct 1, 2013
Authored by Juan Carlos Garcia

UniCredit Bank suffers from cross site request forgery, cross site scripting, and remote shell upload vulnerabilities. They have not responded to the authors notifications.

tags | exploit, remote, shell, vulnerability, xss, csrf
SHA-256 | 4b24c6a6204b07ab95aaa3e329aadafb43c09c8b0febd049f499b640d5f76727
Ebuddy Web Messenger Disclosure / CSRF
Posted Sep 4, 2013
Authored by Juan Carlos Garcia

Ebuddy Web Messenger suffers from index disclosure, cross site request forgery, htaccess file disclosure, and insecure credential transport vulnerabilities.

tags | exploit, web, vulnerability, info disclosure, csrf
SHA-256 | ccaf79bd154471179fb4406fdc64b21ea02903e1d8c4dc8ee30b274d01f17dff
Cetelem Online Bank Cross Site Scripting / Clickjacking
Posted Sep 3, 2013
Authored by Juan Carlos Garcia

Cetelem Online bank suffers from cross site scripting and clickjacking vulnerabilities. The vendor had not responded to the researcher after multiple attempts to reach them. The CSIRT team for the bank notified Packet Storm on 10/14/2013 that the issues have been remediated.

tags | exploit, vulnerability, xss
SHA-256 | 725a5580019aaa28e98f7d7843da1fbb140cb6edd882ae4285924205b58a8f7d
Geonick Social Network Clickjacking / Credential Disclosure
Posted Aug 29, 2013
Authored by Juan Carlos Garcia

Geonick Social Network suffers from a lack of clickjacking protection, it has an insecure crossdomain.xml file, and sends user credentials in the clear.

tags | exploit
SHA-256 | 97a88857ba14577c519450180d5fb5211da072e083d09bb5b1895c33b26737a7
Obehotel CMS Denial Of Service / SQL Injection
Posted Aug 26, 2013
Authored by Juan Carlos Garcia

Obehotel CMS suffers from denial of service, insecure transit, directory listing, and remote SQL injection vulnerabilities.

tags | exploit, remote, denial of service, vulnerability, sql injection
SHA-256 | d5574eb95b9c81f907d0fcbec02ac11f615600255a8fae6dcf88f94ba7394837
FICOBank Information Disclosure / Cross Site Scripting
Posted Aug 23, 2013
Authored by Juan Carlos Garcia

FICOBank suffers from exposed directory listing and cross site scripting vulnerabilities. They do not believe any of this is an issue and if you use them, you should change banks immediately.

tags | exploit, vulnerability, xss
SHA-256 | a3b64ae17ac6373785bfcea917ed3efed819ce567e81d61f13690c93de1a211e
MIT Directory Information Disclosure
Posted Aug 15, 2013
Authored by Juan Carlos Garcia

Massachusetts Institute of Technology suffers form a parent directory information disclosure issue.

tags | exploit, info disclosure
SHA-256 | 25c4c820de4680add586c4f667935a3834dbffdb67c3acffb1699c117aa0e5ac
ZZN SQL Injection / XSS / Credential Disclosure
Posted Aug 9, 2013
Authored by Juan Carlos Garcia

ZZN (Web Hosting and Free email accounts) suffers from cross site scripting, remote blind SQL injection, and credential disclosure vulnerabilities.

tags | exploit, remote, web, vulnerability, xss, sql injection, info disclosure
SHA-256 | 6366cc696316ce5d9a9ad1c083d31746295d4a474bb3f4aeb475ce0ef05f30a9
Zoho Information Disclosure / Mixed Content
Posted Jul 15, 2013
Authored by Juan Carlos Garcia

Zoho suffers from information disclosure due to a lack of a content-type being specified and also appears to use mixed content.

tags | exploit, info disclosure
SHA-256 | d57f3ea5e158c04a53db6f3c8f8158fa024c8439b78c89b7ef0eedc2e2627082
YOPMail XSS / Injection / HTTP Response Splitting
Posted Jun 28, 2013
Authored by Juan Carlos Garcia

YOPMail suffers from cross site scripting, HTTP response splitting, CRLF injection, and session token handling vulnerabilities.

tags | exploit, web, vulnerability, xss
SHA-256 | 695a2946cc39df0b7ae62aedfd486a14f8ffc15c2fc2ef1b909e0eeccfa856ae
Hostinger Web Hosting Cross Site Scripting
Posted Jun 17, 2013
Authored by Juan Carlos Garcia

Hostinger Web Hosting suffers from multiple cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss
SHA-256 | d4df1d9a2179f68c53b64dfbdf8a2a1dd84c602165ca1cac6074386192683ec9
Self-Bank Cross Site Scripting
Posted Jun 10, 2013
Authored by Juan Carlos Garcia

Selfbank.es suffers from multiple cross site scripting vulnerabilities. The author has tried to contact them multiple times but they still have not addressed the issue.

tags | exploit, vulnerability, xss
SHA-256 | c3f66357f373d38ba92b936055d9ff5c490bac66ad80f480d32ccb49d1deaeb7
TESO Web 2.0 SQL Injection
Posted Jun 9, 2013
Authored by Juan Carlos Garcia

TESO Web version 2.0 suffers from a remote SQL injection vulnerability. The author has repeatedly notified the vendor and has received no response.

tags | exploit, remote, web, sql injection
SHA-256 | 109b007b0505bc9569955d793736cad0ba49a4d1fffb9c3900dce2ffb49da8e1
Page 1 of 2
Back12Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close