what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 35 RSS Feed

Files Date: 2011-05-16

7-Technologies IGSS <= v9.00.00 b11063 IGSSdataServer.exe Stack Overflow
Posted May 16, 2011
Authored by Luigi Auriemma, corelanc0d3r, sinn3r, Lincoln | Site metasploit.com

This Metasploit module exploits a vulnerability in the igssdataserver.exe component of 7-Technologies IGSS up to version 9.00.00 b11063. While processing a ListAll command, the application fails to do proper bounds checking before copying data into a small buffer on the stack. This causes a buffer overflow and allows to overwrite a structured exception handling record on the stack, allowing for unauthenticated remote code execution.

tags | exploit, remote, overflow, code execution
advisories | CVE-2011-1567
SHA-256 | d6e50055a18ef8053fcab8d3dbb3013cea1bef5f64706db8cc621234903f31fb
allocPSA 1.7.4 Cross Site Scripting
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A reflected cross site scripting vulnerability in allocPSA version 1.7.4 can be exploited to execute arbitrary JavaScript.

tags | exploit, arbitrary, javascript, xss
SHA-256 | c6d3929e70ce429ecd9432332d70868ebba842b7f609d46a711ea0c0063c3f99
docMGR 1.1.2 Cross Site Scripting
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A reflected cross site scripting vulnerability in docMGR version 1.1.2 can be exploited to execute arbitrary JavaScript.

tags | exploit, arbitrary, javascript, xss
SHA-256 | 71981cc297341251677d9d7c40c9049a5c3f8ea76eb73f58fb860f2b94797246
eFront 3.6.9 Build 10653 Local File Inclusion
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A local file inclusion vulnerability in eFront version 3.6.9 build 10653 can be exploited to include arbitrary files.

tags | exploit, arbitrary, local, file inclusion
SHA-256 | 757d4d3ff27349cbcb4076c56397b29175bb764572af206f95a0de8ef3b1b26a
eFront 3.6.9 Build 10653 Cross Site Scripting
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A reflected cross site scripting vulnerability in eFront version 3.6.9 build 10653 can be exploited to execute arbitrary JavaScript.

tags | exploit, arbitrary, javascript, xss
SHA-256 | e423ef5df13b78150b6b93df88be757d9b632b4929d23d96835f32256985f094
HTML2PDF 4.02 Cross Site Scripting
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A reflected cross site scripting vulnerability in HTML2PDF version 4.02 can be exploited to execute arbitrary JavaScript.

tags | exploit, arbitrary, javascript, xss
SHA-256 | b1643cd1a55ddb0dabefeaff559e6c67d874bbd2bc771f1d91e43238efea560b
Jcow 4.2.1 Local File Inclusion
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A local file inclusion vulnerability in Jcow version 4.2.1 can be exploited to include arbitrary files.

tags | exploit, arbitrary, local, file inclusion
SHA-256 | d691b724a1767a1b7c65676e99b37b35e412f01c91ba255452ddfe3ee8b3b66e
NoticeBoardPro 1.0 Shell Upload
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

An arbitrary upload vulnerability in NoticeBoardPro version 1.0 can be exploited to upload a PHP shell.

tags | exploit, arbitrary, shell, php
SHA-256 | 42eb351b7dcc9619cd585b9ac55004622fee7da9c5c55b7c016edc723f4644a1
NoticeBoardPro 1.0 SQL Injection
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A SQL injection vulnerability in NoticeBoardPro version 1.0 can be exploited to extract arbitrary data. In some environments it may be possible to create a PHP shell.

tags | exploit, arbitrary, shell, php, sql injection
SHA-256 | 7bc77fa2826526d53979b3c39a01fcc657ba86945a552ee4b77da29a7dfbdbf1
openQRM 4.8 Cross Site Scripting
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A reflected cross site scripting vulnerability in openQRM version 4.8 can be exploited to execute arbitrary JavaScript.

tags | exploit, arbitrary, javascript, xss
SHA-256 | d7d2209a239bb9bd6b5d18d36806bc27bb94b901bcb654fbf6cc920d8ef9a918
phpMyChat Plus 1.93 Local File Inclusion
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A local file inclusion vulnerability in phpMyChat Plus version 1.93 can be exploited to include arbitrary files.

tags | exploit, arbitrary, local, file inclusion
SHA-256 | 7473613dd8fef214fe65bb5d88818fc794c6df66621c4633c4d8b3eecfdb2796
Vanilla Forum 2.0.17.9 Local File Inclusion
Posted May 16, 2011
Authored by AutoSec Tools | Site autosectools.com

A local file inclusion vulnerability in Vanilla Forum version 2.0.17.9 can be exploited to include arbitrary files.

tags | exploit, arbitrary, local, file inclusion
SHA-256 | 6d6f7abc83ce79333088d0061f3a68c539a14aad653d858429bd3497a68ee023
Mandriva Linux Security Advisory 2011-087
Posted May 16, 2011
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2011-087 - The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service X position or Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions. The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation. The updated packages have been upgraded to 2.28.3 which is not vulnerable to these issues.

tags | advisory, remote, denial of service
systems | linux, mandriva
advisories | CVE-2011-0904, CVE-2011-0905
SHA-256 | 071cbada81358e2a216406d81427278602a3d81ce6f686ff9d33a09a53583363
WebTech 2011 Conference Call For Papers
Posted May 16, 2011
Site webtechcon.de

The WebTech 2011 Call For Papers has been announced. It will take place from October 10th through the 12th, 2011 in Mainz, Germany.

tags | paper, conference
SHA-256 | 05fb17867fb8f9a278e4ade37bcbfaef101b0948e68ea9c0d1504bcc445af491
Novell LDAP-SSL Daemon Denial Of Service
Posted May 16, 2011
Authored by Knud | Site nsense.fi

nSense Vulnerability Research Security Advisory - It is possible to cause a denial of service in Novell's LDAP-SSL daemon due to the system blindly allocating a user-specified amount of memory. Exploiting the issue on a Netware system will cause a system-wide DoS condition.

tags | exploit, denial of service
SHA-256 | 972238c95111a6fb64022b85c2982b7c92402fed540695e47f81e34f5d96e993
Vmware vSphere Management Assistant (vMA) Privilege Escalation
Posted May 16, 2011
Authored by @drk1wi

Vmware vSphere Management Assistant (vMA) suffers from a local privilege escalation vulnerability.

tags | exploit, local
SHA-256 | 00cf8c44a6d902ca66053c39cade132def8aa3357eed4f38516bf8a5094862aa
QuickRecon 0.3
Posted May 16, 2011
Authored by Filip Szymanski

QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.

Changes: Qt4 based GUI. Improved Code.
tags | tool, scanner, python
systems | unix
SHA-256 | 0222c6eae1b59eab957306ca2b00a8c50513132b563bbd76b327300a3b99b354
Steam Cloud Denial Of Service
Posted May 16, 2011
Authored by David R. Klein

Steam Cloud suffers from a denial of service vulnerability.

tags | exploit, denial of service
SHA-256 | 50dd11160d8ffe10cc9dbcc013fe67d028576b3170b94e14d7e4a9c051f53988
Mandriva Linux Security Advisory 2011-086
Posted May 16, 2011
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2011-086 - A race condition flaw was found in the PolicyKit pkexec utility and polkitd daemon. A local user could use this flaw to appear as a privileged user to pkexec, allowing them to execute arbitrary commands as root by running those commands with pkexec. The updated packages have been patched to correct this issue.

tags | advisory, arbitrary, local, root
systems | linux, mandriva
advisories | CVE-2011-1485
SHA-256 | 4d1378d24d238c4a412b7901ca0ad28b94cd0c13aeb47449cf04e14e9c9fa2d1
BadAss 0.5 Beta
Posted May 16, 2011
Authored by blass

BadAss is a Ruby script that makes it very easy to perform cracking attacks, port scanning, and more.

Changes: Interface re-written from scratch. New ruby scripts added. Various other additions.
tags | tool, ruby
systems | unix
SHA-256 | f60b8cfe78a679c56d4b810db3e6e9bc7ced2dc2f8f463b2b80af1729f0bf974
Secunia Security Advisory 44600
Posted May 16, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Alexander Gavrun has discovered a vulnerability in Winamp, which can be exploited by malicious people to compromise a user's system.

tags | advisory
SHA-256 | 1b81d4bf7f2645bba055cce2682a81346ec892113e638d0b765e68ff07758372
Secunia Security Advisory 44513
Posted May 16, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in GuppY, which can be exploited by malicious people to conduct cross-site request forgery attacks.

tags | advisory, csrf
SHA-256 | 29ca1e620a548ca571f038746ba441986dcb09ab6837d413ddfb4c8ec755116c
Secunia Security Advisory 44592
Posted May 16, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - AutoSec Tools has discovered a vulnerability in allocPSA, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | b14d0e35a6bc5ba5a9b304e7903d9f47ef82280d5a7e736490e20a9402324878
Secunia Security Advisory 44577
Posted May 16, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Some vulnerabilities have been reported in Crucible, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, vulnerability, xss
SHA-256 | c2462b8ab7dd641a36ad005e0f660323498cfe375aaf1e61d1c9b9eed046731b
Secunia Security Advisory 44619
Posted May 16, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Fedora has issued an update for perl-Mojolicious. This fixes two vulnerabilities, where one has an unknown impact and the other can be exploited by malicious users to conduct script insertion attacks.

tags | advisory, perl, vulnerability
systems | linux, fedora
SHA-256 | 17a7d4e9fc0400f414731fe81b37e1d846afe1055296df5ddcb19f38638203e3
Page 1 of 2
Back12Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close