exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 176 - 200 of 578 RSS Feed

Files from High-Tech Bridge SA

Real NameHigh-Tech Bridge SA
Email addressadvisory at htbridge.com
Websitewww.htbridge.com
First Active2010-04-20
Last Active2016-08-03
View User Profile

Personal Background

High-Tech Bridge SA (htbridge.com) provides businesses and organizations with world-class information security services. High-Tech Bridge Security Research Lab (unit of High-Tech Bridge's R&D Department) regularly releases HTB Advisories that are aimed to to help various software vendors to improve security of their products. High-Tech Bridge's auditors also try to share their knowledge with the industry by publishing White Papers on information security and ethical hacking topics.


CMS Made Simple 1.11.2 Cross Site Request Forgery
Posted Nov 8, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

CMS Made Simple version 1.11.2 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
advisories | CVE-2012-5450
SHA-256 | 56b7ba7d70e2826a7429d5920fa59759fa5a8af3573cf4be2e6001b5dd4f93f6
OrangeHRM 2.7.1-rc.1 Cross Site Request Forgery / SQL Injection
Posted Nov 7, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

OrangeHRM version 2.7.1-rc.1 suffers from cross site request forgery and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, csrf
advisories | CVE-2012-5367
SHA-256 | 439484ab92a26f93c029153c595de5755d66408db277b54f3d4df86561bf82d6
LibreOffice Suite 3.5.5.3 Denial Of Service
Posted Nov 7, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

LibreOffice Suite version 3.5.5.3 suffers from multiple null pointer denial of service vulnerabilities. Multiple proof of concepts included.

tags | exploit, denial of service, vulnerability, proof of concept
systems | linux
advisories | CVE-2012-4233
SHA-256 | e35f8a5b17053ef5bbb7453b17da615dd29fdbd2c8de140c6974ca04b33f0fb0
jCore 1.0pre Cross Site Scripting / SQL Injection
Posted Oct 18, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

jCore version 1.0pre suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
advisories | CVE-2012-4231, CVE-2012-4232
SHA-256 | 6b5298a41aa2820b67dc3beb4a6b02db1aaee7603772138dd6228a587a308157
Subrion CMS 2.2.1 XSS / CSRF / SQL Injection
Posted Oct 18, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Subrion CMS version 2.2.1 suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection, csrf
advisories | CVE-2012-4771, CVE-2012-4772, CVE-2012-4773
SHA-256 | a3cf7fcdf1b5f6d220a577633d480f22b716b77a1b6f6819efe7e82d7b6fc0dd
ATutor AContent 1.2 XSS / Authentication / SQL Injection
Posted Oct 18, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

ATutor AContent versions 1.2 and below suffer from improper authentication, cross site scripting, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
advisories | CVE-2012-5167, CVE-2012-5168, CVE-2012-5169
SHA-256 | f884299c5d9976c978753e2b78b0f47541e45479ec64ddb6f85cd4a678ba506e
Samsung Kies 2.3.2.12054_20 NULL Pointer Dereference / Access Control
Posted Oct 15, 2012
Authored by High-Tech Bridge SA, Frederic Bourla | Site htbridge.com

Samsung Kies version 2.3.2.12054_20 suffers from a null pointer dereference and multiple improper access control vulnerabilities.

tags | exploit, vulnerability
advisories | CVE-2012-3806, CVE-2012-3807, CVE-2012-3808, CVE-2012-3809, CVE-2012-3810
SHA-256 | 3be5d1fc00baef95418066a6e177e3648f8af24d33460c51813fe80c0adeb108
Adobe Flash Player Integer Overflow Analysis
Posted Oct 12, 2012
Authored by Brian Mariani, High-Tech Bridge SA, Frederic Bourla | Site htbridge.com

This whitepaper is a thorough analysis of the Adobe Flash Player integer overflow vulnerability and documented in CVE-2012-1535.

tags | paper, overflow
advisories | CVE-2012-1535
SHA-256 | e46a3e43ec3e9446bcf1fa801d93b9d52396891905bbbce417daada24526d84c
OpenX 2.8.10 Cross Site Scripting / SQL Injection
Posted Oct 11, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

OpenX version 2.8.10 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
advisories | CVE-2012-4989, CVE-2012-4990
SHA-256 | d484cead504afbaaedbee4354a2ee6cdeaaafcec1c5ad0426bb8c95c12f4be46
Microsoft Windows Privilege Escalation
Posted Oct 10, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

High-Tech Bridge Security Research Lab has discovered a vulnerability in Microsoft Windows which could be exploited to escalate privileges under certain conditions. The vulnerability exists due to the "IKE and AuthIP IPsec Keying Modules" system service, which tries to load the wlbsctrl.dll DLL that is missing after default Windows installation. Proof of concept included.

tags | exploit, proof of concept
systems | linux, windows
SHA-256 | 59c748e21d43b8cf7dd9c2c3ce4ae6dbd13341240e0cfa60bbf3d2ee4d85b88e
Template CMS 2.1.1 Cross Site Request Forgery / Cross Site Scripting
Posted Oct 3, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Template CMS version 2.1.1 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
advisories | CVE-2012-4901, CVE-2012-4902
SHA-256 | f8abf37639cf0553f4391d208e25723d53d985a4a7b9cc5ee591c7708a514809
TestLink 1.9.3 Cross Site Request Forgery
Posted Sep 6, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

TestLink version 1.9.3 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
advisories | CVE-2012-2275
SHA-256 | 736b804ed14899a61e45af9653a9658234392141a3b1244d4491cc912560e8b1
Kayako Fusion 4.40.1148 Cross Site Scripting
Posted Sep 6, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Kayako Fusion version 4.40.1148 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2012-3233
SHA-256 | 22c8939a4ff8f7653b41b96e3d5e28adb2daf84ed90611ca28c98c0000ba9ed9
Flogr 2.5.6 Cross Site Scripting
Posted Sep 6, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Flogr version 2.5.6 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2012-4336
SHA-256 | 121f75b7018579ac3d30797c9d6d69498ac7e2be3d261bd041823c624da988d0
How To Use PyDbg As A Powerful Multitasking Debugger
Posted Sep 5, 2012
Authored by Brian Mariani, High-Tech Bridge SA, Frederic Bourla | Site htbridge.com

Since its introduction in 2006, PyDbg has become an essential tool for security researchers and reverse engineers. It is mainly used to discover various software vulnerabilities and weaknesses, as well to analyze malware and perform computer forensics. The present publication is aimed to provide a reader with an introduction to the Python based debugger and deliver practical and real examples of this powerful security tool usage.

tags | paper, vulnerability, python
SHA-256 | fe6ebddfdd8a95029596ddb6ff5ad30b306c35a3bb7552b5ec2d24ca4413b8b2
Phorum 5.2.18 Cross Site Scripting
Posted Aug 30, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Phorum version 5.2.18 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2012-4234
SHA-256 | eacb48244f80206c5c20974e626a07b89b72ecd38320b50f7390d840e42bcd13
PrestaShop 1.4.7 / 1.4.8 Cross Site Scripting
Posted Aug 30, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

PrestaShop versions 1.4.7 and 1.4.8 suffer from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2012-2517
SHA-256 | 94e63abd47975a241e1fd867909d2fecfd6d076014bc0a3efa593aeb09e59263
phpList 2.10.18 Cross Site Scripting / SQL Injection
Posted Aug 9, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

phpList version 2.10.18 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
advisories | CVE-2012-3952, CVE-2012-3953
SHA-256 | 7c2f52b5334b8d1ae75b3fffb38e7c18fedbae4934a65a5cc1c9ab975dea72d9
PBBoard 2.1.4 SQL Injection / Improper Authentication / Broken Access Control
Posted Aug 9, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

PBBoard version 2.1.4 suffers from improper authentication, improper access control, and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, bypass
advisories | CVE-2012-4034, CVE-2012-4035, CVE-2012-4036
SHA-256 | 98c660124db3dfdff27f3497939655798807cd19db3c0489fbf39341a0590cb1
Redaxo 4.4 Cross Site Scripting
Posted Jul 25, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Redaxo version 4.4 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2012-3869
SHA-256 | 44fcafd5bf41a508f40719e15f1cb1569a6d62987e638d5f77a211a346b98692
CVE-2012-1889: Security Update Analysis
Posted Jul 23, 2012
Authored by Brian Mariani, High-Tech Bridge SA, Frederic Bourla | Site htbridge.com

Since the 30th of May 2012 hackers were abusing the Microsoft XML core services vulnerability. The 10th of July 2012 Microsoft finally published a security advisory which fixes this issue. The present document and video explains the details about this fix. As a lab test they used a Windows XP workstation with Service Pack 3. The Internet explorer version is 6.0.

tags | paper
systems | windows
advisories | CVE-2012-1889
SHA-256 | 0663e2de1f39f4495717f0290d861ffdd11a1fe7f2edc6deba2d85db93bac5bd
Kajona 3.4.1 Cross Site Scripting
Posted Jul 12, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Kajona version 3.4.1 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2012-3805
SHA-256 | d75c046fbf006dc94fb86ff631caec3c44a0b3c00a0d32c9e2e3703cc7e3ae60
Microsoft XML Core Services Uninitialized Memory
Posted Jul 5, 2012
Authored by Brian Mariani, High-Tech Bridge SA, Frederic Bourla | Site htbridge.com

This is a thorough analysis of the Microsoft XML core services uninitialized memory vulnerability as noted by CVE-2012-1889. It includes proof of concept data to trigger the issue and goes through the flow.

tags | paper, proof of concept
advisories | CVE-2012-1889
SHA-256 | 71478922d4d7dd398af9e4e90d1f859e3494d8ddf266086e502d50612e95667a
Webmatic 3.1.1 Blind SQL Injection
Posted Jul 4, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Webmatic version 3.1.1 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2012-3350
SHA-256 | 5df53c25fc086e653b42c737dfd26a462ef9860efd1b43b10ec8613e53d95ab9
Web@All 2.0 Cross Site Request Forgery / Cross Site Scripting
Posted Jun 21, 2012
Authored by High-Tech Bridge SA | Site htbridge.com

Web@All version 2.0 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss, csrf
advisories | CVE-2012-3231, CVE-2012-3232
SHA-256 | d25d5ad1ddb1de7212645fc16e7b47dc50410239fbb34e4de53c1aac5b358024
Page 8 of 24
Back678910Next

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    6 Files
  • 19
    Jul 19th
    34 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    19 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close