exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 34 RSS Feed

Files Date: 2011-03-08

Majordomo2 Directory Traversal
Posted Mar 8, 2011
Authored by Nikolas Sotiriu

Majordomo2 suffers from a directory traversal vulnerability in the help command. The parameter named extra is not properly sanitized. Versions 20110203 and below are affected.

tags | exploit
advisories | CVE-2011-0063
SHA-256 | a56132a9257c31bde8e4caffddc1080e11f6ed79939595cb7bcf42ff440d659b
Mandriva Linux Security Advisory 2011-044
Posted Mar 8, 2011
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2011-044 - This advisory updates wireshark to the latest version (1.2.15), fixing several security issues. Wireshark 1.5.0, 1.4.3, and earlier frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a malformed file. Heap-based buffer overflow in wiretap/dct3trace.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long record in a Nokia DCT3 trace file. wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) via a pcap-ng file that contains a large packet-length field. Various other issues have been addressed as well.

tags | advisory, remote, denial of service, overflow
systems | linux, mandriva
advisories | CVE-2011-0538, CVE-2011-0713, CVE-2011-1139, CVE-2011-1140, CVE-2011-1141, CVE-2011-1142
SHA-256 | 226b5891bf60e311e70b2e108a9605a209856a8dce1a91a24138ea6d7b6b5cdf
Icinga 1.3.0 / 1.2.1 Cross Site Scripting
Posted Mar 8, 2011
Authored by Stefan Schurtz

Icinga versions 1.3.0 and 1.2.1 suffer from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 5504d3698e652a4b60d43cd8c74281f9ffb976cc20149c26f1009b0a0f445ddf
PhotoSmash 1.0.1 Cross Site Scripting
Posted Mar 8, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

PhotoSmash WordPress plugin version 1.0.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a84959832cab5cd1fceda9fd23285ebd309435c85e42b54c57c87b35c1f9c0ff
Mandos Encrypted File System Unattended Reboot Utility 1.3.0
Posted Mar 8, 2011
Authored by Teddy | Site fukt.bsnet.se

The Mandos system allows computers to have encrypted root file systems and at the same time be capable of remote or unattended reboots. The computers run a small client program in the initial RAM disk environment which will communicate with a server over a network. All network communication is encrypted using TLS. The clients are identified by the server using an OpenPGP key that is unique to each client. The server sends the clients an encrypted password. The encrypted password is decrypted by the clients using the same OpenPGP key, and the password is then used to unlock the root file system.

Changes: Server and utilities have been updated for Python 2.6. Client bugfixes - the password-prompt plugin does not conflict with Plymouth. initramfs is also updated when purging a package.
tags | remote, root
systems | linux, unix
SHA-256 | bb2b506dabbf44526c7a55763a6d78f9c99344fde7b3dcd1de0cb29464834c53
EzPub Simple Classic ASP CMS SQL Injection
Posted Mar 8, 2011
Authored by p0pc0rn

EzPub Simple Classic ASP CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
SHA-256 | dc9ee4cd7403e920bfc04f13411d03a8a3e99d9c1383f3e409abb0d54970b958
1 Flash Gallery 0.2.5 Cross Site Scripting / SQL Injection
Posted Mar 8, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

1 Flash Gallery WordPress plugin version 0.2.5 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 6ede757867af42703688c166b37d8c04a8397aacd56eec2f7a9132e3f8ce867f
Inline Gallery 0.3.9 Cross Site Scripting
Posted Mar 8, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

Inline Gallery WordPress plugin version 0.3.9 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 3c2298acac7b2204a9ca7b68a1ae36404404ac8cf78c73ec3c3c3c03ed1b105f
HP Security Bulletin HPSBUX02641 SSRT100412
Posted Mar 8, 2011
Authored by HP | Site hp.com

HP Security Bulletin HPSBUX02641 SSRT100412 - A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM) for HP-UX, Linux, Solaris, and Windows running Java. The vulnerability could be remotely exploited to create a Denial of Service (DoS). Revision 1 of this advisory.

tags | advisory, java, denial of service
systems | linux, windows, solaris, hpux
advisories | CVE-2010-4476
SHA-256 | 7de2ad982e2727b8e870feaa182fe6e5d5fdfb85e360494687337c5c582a1bdd
GRAND Flash Album Gallery 0.55 SQL Injection / File Disclosure
Posted Mar 8, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

GRAND Flash Album Gallery WordPress plugin version 0.55 suffers from remote SQL injection and file disclosure vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, info disclosure
SHA-256 | 2e380e18f2ca3a4c01a87b1b6c137237d8ca4b642dc12ce6c0f32975a86bf800
Linux Kernel caiaq USB Drivers Buffer Overflow
Posted Mar 8, 2011
Authored by Rafael Dominguez Vega | Site labs.mwrinfosecurity.com

A buffer overflow vulnerability in the caiaq USB drivers in Linux has been identified. These drivers are in the kernel tree and installed by default in most Linux distributions. This vulnerability could be exploited in order to execute arbitrary code by an attacker with physical access to the system.

tags | advisory, overflow, arbitrary, kernel
systems | linux
advisories | CVE-2011-0712
SHA-256 | 50ee3bf5cf01b2e96fee9bdabe9d4b1efa5b3f58c6f22cb7f2a1550e353f5ed3
Nokia N97 Playlist Proof Of Concept
Posted Mar 8, 2011
Authored by KedAns-Dz

Nokia N97 .m3u playlist crash proof of concept exploit.

tags | exploit, denial of service, proof of concept
SHA-256 | 7f09b1a70d0c276a4d3ed229be13ddb6de013a627a045c4f829c4bbc9bc5c45c
Movavi VideoSuite 8.0 MovieEditor.exe Buffer Overflow
Posted Mar 8, 2011
Authored by KedAns-Dz

Movavi VideoSuite version 8.0 MovieEditor.exe local crash buffer overflow proof of concept exploit.

tags | exploit, overflow, local, proof of concept
SHA-256 | e185b19aa779684dd5463ac9fe95b0ac6768d2d89f498d49890fd694218eb6d0
Movavi VideoSuite 8.0 MediaPlayer.exe Buffer Overflow
Posted Mar 8, 2011
Authored by KedAns-Dz

Movavi VideoSuite version 8.0 MediaPlayer.exe buffer overflow exploit that spawns a reverse shell.

tags | exploit, overflow, shell
SHA-256 | be281d18ffd2d3e2019a0557e5c5b229b7651bde374585a97770dfbbd3e1ca75
Movavi VideoSuite 8.0 SlideShow.exe Buffer Overflow
Posted Mar 8, 2011
Authored by KedAns-Dz

Movavi VideoSuite version 8.0 SlideShow.exe local crash buffer overflow proof of concept exploit.

tags | exploit, overflow, local, proof of concept
SHA-256 | b8815006777db4d9f469e36b6ada08850a6d7b38c0be8e655bb1e55df7322a04
Mandriva Linux Security Advisory 2011-043
Posted Mar 8, 2011
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2011-043 - A buffer overflow was discovered in libtiff which allows remote attackers to execute arbitrary code or cause a denial of service via a crafted TIFF image with CCITT Group 4 encoding.

tags | advisory, remote, denial of service, overflow, arbitrary
systems | linux, mandriva
advisories | CVE-2011-0192, CVE-2009-2347, CVE-2010-2065
SHA-256 | a30c069b2a4cc6efb9588b6a66dfd73bfd71758866bd0849dc058e1257a3f581
Marco Monaco SQL Injection
Posted Mar 8, 2011
Authored by eXeSoul

Web Development by Marco Monaco suffers from a remote SQL injection vulnerability.

tags | exploit, remote, web, sql injection
SHA-256 | 36d8ea4b5fbc6e81c076e1a5c6f8d29bfc615fa0132595f40a4a7245d1dd90ad
.NET Runtime Optimization Service Privilege Escalation
Posted Mar 8, 2011
Authored by XenoMuta

.NET runtime optimization service privilege escalation exploit that leverages the fact that the service's EXE file can be overwritten by any non-admin domain user and local power users. This exploit compiles to a service that uses the original service's id.

tags | exploit, local
SHA-256 | 744f7672e14b5f0fc0764ea74c1519e7a0ebfe6e8883fc42b8bab17499280a19
VMware Security Advisory 2011-0004
Posted Mar 8, 2011
Authored by VMware | Site vmware.com

VMware Security Advisory 2011-0004 - Service Location Protocol daemon (SLPD) denial of service issue and ESX 4.0 Service Console OS (COS) updates for bind, pam, and rpm.

tags | advisory, denial of service, protocol
advisories | CVE-2010-2059, CVE-2010-3316, CVE-2010-3435, CVE-2010-3609, CVE-2010-3613, CVE-2010-3614, CVE-2010-3762, CVE-2010-3853
SHA-256 | 719826a83686579aa0ee4f4f4daf886e176fc92fd4d140eec35f2f8d630f07d1
2010 Annual Study - U.S. Cost Of A Data Breach
Posted Mar 8, 2011
Authored by Ponemon Institute, Symantec

Whitepaper called 2010 Annual Study: U.S. Cost of a Data Breach. Compliance pressures, cyber attacks targeting sensitive data drive leading IT organizations to respond quickly and pay more. This is a benchmark study of 51 U.S. companies about the financial impact, customer turnover and preventive solutions related to breaches of sensitive information.

tags | paper
SHA-256 | 9cc176c8381bb68607f066dfc318ae42eb811a57dcdcb62a70a04cca68503a77
Joomla PR Local File Inclusion
Posted Mar 8, 2011
Authored by KedAns-Dz

The Joomla PR component suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | d05fb5fca7c651cc513d71b01a1e79d24d078f660c03fabb8a1e67cf2830d010
Cool Video Gallery 1.3 WordPress Plugin Path Disclosure
Posted Mar 8, 2011
Authored by High-Tech Bridge SA | Site htbridge.com

The Cool Video Gallery WordPress plugin version 1.3 suffers from a path disclosure vulnerability.

tags | exploit, info disclosure
SHA-256 | d8c5f2656a9552fad9a508757ad735ee92af63b934a3414eea7679f77371b31b
PHP-Nuke Shell Upload
Posted Mar 8, 2011
Authored by h311 c0d3

PHP-Nuke suffers from a shell upload vulnerability.

tags | exploit, shell, php
SHA-256 | 97e017dd97ff9b8107b0a90088dcb0fe6da0fa7b3b64f3e82a40e383f4b1a318
Multi Threaded TCP Port Scanner 1.1
Posted Mar 8, 2011
Authored by SecPoint | Site secpoint.com

This is a basic TCP SYN scanner that is multi-threaded.

Changes: Added port changing functionality.
tags | tool, scanner, tcp
systems | unix
SHA-256 | 6697537b3cd72ac8405cf890c3f4b8cfb8b7cc6353dc99a998f585dbbd406d21
Secunia Security Advisory 43437
Posted Mar 8, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A weakness has been reported in GNOME Display Manager, which can lead to unexpected behavior with potentially security relevant implications.

tags | advisory
SHA-256 | f7f94c9656fcd115243b2e6a2525b74fe85c9c367311e42fa6de12b974c1dc91
Page 1 of 2
Back12Next

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close