exploit the possibilities
Showing 1 - 25 of 57 RSS Feed

Files Date: 2009-04-16

MagicISO Heap Overflow
Posted Apr 16, 2009
Authored by Stack | Site v4-team.com

MagicISO CCD/Cue local heap overflow proof of concept exploit.

tags | exploit, overflow, local, proof of concept
MD5 | d0c77263a385d2009c8736b1c54b6d73
chCounter 3.1.3 SQL Injection
Posted Apr 16, 2009
Authored by tmh, Lainux

chCounter version 3.1.3 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
MD5 | 6013e665e13d93c9c56d25aed0f52edb
SMA-DB 0.3.13 Remote File Inclusion
Posted Apr 16, 2009
Authored by JosS | Site spanish-hackers.com

SMA-DB version 0.3.13 suffers from multiple remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, code execution, file inclusion
MD5 | 2b1172fc21875e15700edc73c31140ba
cpCommerce 1.2.8 Blind SQL Injection
Posted Apr 16, 2009
Authored by NoGe

cpCommerce version 1.2.8 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 43077fd50880301ab96cb65602dc75a7
Gentoo Linux Security Advisory 200904-15
Posted Apr 16, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200904-15 - An error in mpg123 might allow for the execution of arbitrary code. The vendor reported a signedness error in the store_id3_text() function in id3.c, allowing for out-of-bounds memory access. Versions less than 1.7.2 are affected.

tags | advisory, arbitrary
systems | linux, gentoo
advisories | CVE-2009-1301
MD5 | 15e85ae8c6e52124d209323e0c29efc2
Ubuntu Security Notice 760-1
Posted Apr 16, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-760-1 - It was discovered that CUPS did not properly check the height of TIFF images. If a user or automated system were tricked into opening a crafted TIFF image file, a remote attacker could cause a denial of service or possibly execute arbitrary code with user privileges. In Ubuntu 7.10, 8.04 LTS, and 8.10, attackers would be isolated by the AppArmor CUPS profile.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2009-0163
MD5 | d38359ae4536587eaeea7ea5915fec87
Ubuntu Security Notice 759-1
Posted Apr 16, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-759-1 - Will Dormann, Alin Rad Pop, Braden Thomas, and Drew Yao discovered that poppler contained multiple security issues in its JBIG2 decoder. If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program.

tags | advisory, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2009-0146, CVE-2009-0147, CVE-2009-0166, CVE-2009-0799, CVE-2009-0800, CVE-2009-1179, CVE-2009-1180, CVE-2009-1181, CVE-2009-1182, CVE-2009-1183, CVE-2009-1187, CVE-2009-1188
MD5 | a43a33a30ef0000bd0f3cc2a4ed6b10e
Apache Geronimo Cross Site Request Forgery
Posted Apr 16, 2009
Site dsecrg.com

Apache Geronimo Application Server versions 2.1 through 2.1.3 suffer from multiple cross site request forgery vulnerabilities.

tags | exploit, vulnerability, csrf
advisories | CVE-2009-0039
MD5 | 8fdc6c35c9122287c7a9fd49de8856e9
Apache Geronimo Cross Site Scripting
Posted Apr 16, 2009
Site dsecrg.com

Apache Geronimo Application Server versions 2.1 through 2.1.3 suffer from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2009-0038
MD5 | f854fa4f33005b4677a8f70f32e711bd
Apache Geronimo Directory Traversal
Posted Apr 16, 2009
Site dsecrg.com

Apache Geronimo Application Server versions 2.1 through 2.1.3 suffer from a directory traversal file upload vulnerability.

tags | advisory, file upload
advisories | CVE-2008-5518
MD5 | 92ff869ef57bdd6cb65e66edf4765131
Razor CMS 0.3RC2 XSS / Disclosure / Execution
Posted Apr 16, 2009
Authored by Jeremi Gosney

Razor CMS version 0.3RC2 suffers from cross site scripting, weak file permissions leaking credentials, and arbitrary php code execution vulnerabilities.

tags | exploit, arbitrary, php, vulnerability, code execution, xss, info disclosure
MD5 | fabc9ae5fa5547ede7d47cfc47c37a43
DNS Tools Remote Command Execution
Posted Apr 16, 2009
Authored by SirGod | Site insecurity.ro

DNS Tools PHP Digger suffers from a remote command execution vulnerability.

tags | exploit, remote, php
MD5 | 3071a7831f3a1428fef70989512bc59e
Miniweb Buffer Overflow
Posted Apr 16, 2009
Authored by e.wiZz!

The Miniweb webserver suffers from a buffer overflow vulnerability when a URI longer than 120 bytes is requested.

tags | exploit, overflow
MD5 | a19152f8054041359a0c0cb34d61f6c5
Miniweb Source Disclosure
Posted Apr 16, 2009
Authored by e.wiZz!

The Miniweb webserver suffers from source disclosure vulnerabilities.

tags | exploit, vulnerability, info disclosure
MD5 | a6bd24d83103eba57b49aeeadf61d941
Digital Defense VRT Advisory 2009.23
Posted Apr 16, 2009
Authored by Digital Defense, r@b13$, David Marshall | Site digitaldefense.net

Apache ActiveMQ version 5.2.0 suffers from multiple cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
MD5 | 730bcdba54ba8bcb45c891039e83c7e2
webSPELL 4.2.0c XSS Cookie Stealing
Posted Apr 16, 2009
Authored by YEnH4ckEr

webSPELL version 4.2.0c suffers from a BBCode bypass cross site scripting cookie stealing vulnerability.

tags | exploit, xss
MD5 | 7f0686dc0a504a7d8fc47cc8479daad3
Online Password Manager 4.1 Insecure Cookie
Posted Apr 16, 2009
Authored by ZoRLu

Online Password Manager version 4.1 suffers from an insecure cookie handling vulnerability.

tags | exploit, insecure cookie handling
MD5 | 14b9cd5c70a11ad7c667d2819c1f290f
NetHoteles SQL Injection
Posted Apr 16, 2009
Authored by Dns-Team | Site dns-team.com

NetHoteles versions 2.0 and 3.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection, bypass
MD5 | 0f9b8c4a89c3bce865ed0a6250aa9c87
Debian Linux Security Advisory 1772-1
Posted Apr 16, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1772-1 - Sebastian Kramer discovered two vulnerabilities in udev, the /dev and hotplug management daemon.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2009-1185, CVE-2009-1186
MD5 | b3f3ea7fe0eba5dd6681b2acc9340bf3
Danske Bank e-Sec Control Module Error Logging Buffer Overflow
Posted Apr 16, 2009
Authored by Carsten Eiram | Site secunia.com

Secunia Research has discovered a vulnerability in Danske Bank Danske e-Sec Control Module ActiveX control, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused by a boundary error in DanskeSikker.ocx within an error logging function. This can be exploited to cause a stack-based buffer overflow by passing overly long input to certain methods when the ActiveX control has been initialised in a specific manner. Successful exploitation allows execution of arbitrary code when e.g. visiting a malicious web site. Version 3.1.0.48 of DanskeSikker.ocx is affected.

tags | advisory, web, overflow, arbitrary, activex
advisories | CVE-2008-1107
MD5 | 67e14bef91ae6dea80fb83dabc256986
APEX Password Hash Disclosure
Posted Apr 16, 2009
Authored by Alexander Kornbrust | Site red-database-security.com

Unprivileged database users can see password hashes in APEX version 3.0.

tags | exploit, info disclosure
advisories | CVE-2009-0981
MD5 | 9b427a240f309953a54a45c86cfb03a5
DBMS_AQADM_SYS SQL Injection
Posted Apr 16, 2009
Authored by Franz Hull | Site red-database-security.com

The package DBMS_AQADM_SYS contains a SQL injection vulnerability. Oracle versions 9.2.0.8 through 10.2.0.3 are affected.

tags | advisory, sql injection
advisories | CVE-2009-0977
MD5 | 81ea5e5cbda3261558cac5a966655936
DBMS_AQIN SQL Injection
Posted Apr 16, 2009
Authored by Alexander Kornbrust | Site red-database-security.com

The package DBMS_AQIN contains a SQL injection vulnerability in the procedure DEQ_EXEJOB. Oracle versions 10.1.0.5 through 11.1.0.7 are affected.

tags | advisory, sql injection
advisories | CVE-2009-0992
MD5 | 866f9e1ee4fe79cde7302249f4e73b68
Phorum Cross Site Scripting / Request Forgery
Posted Apr 16, 2009
Authored by C1c4Tr1Z

Phorum versions 5.2.10 and below suffer from cross site scripting and cross site request forgery vulnerabilities.

tags | exploit, vulnerability, xss, csrf
MD5 | 8091104d3b5ff26d919f9b2bcad6f9ba
Geeklog 1.5.2 SQL Injection
Posted Apr 16, 2009
Authored by Nine:Situations:Group | Site retrogod.altervista.org

Geeklog versions 1.5.2 and below savepreferences()/*blocks[] remote SQL injection exploit.

tags | exploit, remote, sql injection
MD5 | 4d2e1e0e03c6aada4e9a5a57aaf47182
Page 1 of 3
Back123Next

File Archive:

March 2021

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    19 Files
  • 2
    Mar 2nd
    15 Files
  • 3
    Mar 3rd
    30 Files
  • 4
    Mar 4th
    13 Files
  • 5
    Mar 5th
    9 Files
  • 6
    Mar 6th
    0 Files
  • 7
    Mar 7th
    0 Files
  • 8
    Mar 8th
    0 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    0 Files
  • 14
    Mar 14th
    0 Files
  • 15
    Mar 15th
    0 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    0 Files
  • 21
    Mar 21st
    0 Files
  • 22
    Mar 22nd
    0 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close