exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 193 RSS Feed

Files Date: 2004-03-01 to 2004-03-31

cpanelXSS910.txt
Posted Mar 23, 2004
Authored by Fable

Cpanel version 9.1.0-STABLE 93 is susceptible to cross site scripting attacks.

tags | advisory, xss
SHA-256 | 20c3bdf8e4b2a726db63def0c72d5806799896bda6eb6b6f619e27b3a22a4d22
gm005-mc.txt
Posted Mar 23, 2004
Site security.greymagic.com

GreyMagic Security Advisory GM#005-MC - Both Yahoo and Hotmail are susceptible to cross site scripting attacks.

tags | advisory, xss
SHA-256 | e4ee9aa186ad94384d63d64398e181264a2f7be0a28d2b43868db54160ea73cf
wsftp402eval4.txt
Posted Mar 23, 2004
Authored by Hugh Mann

Ipswitch WS_FTP server version 4.0.2.EVAL has a flaw that allows a remote attacker that ability to read any memory address. With the right address, the user can cause a buffer overflow and execute arbitrary code as SYSTEM.

tags | advisory, remote, overflow, arbitrary
SHA-256 | 3cb9ce74977358040d15ba38c7f849fd531dd829829d647e0922398a87feb947
wsftp402eval3.txt
Posted Mar 23, 2004
Authored by Hugh Mann

Ipswitch WS_FTP server version 4.0.2.EVAL allows for a local attacker with program execution privileges to run anything with SYSTEM privileges. Full step-by-step exploitation given.

tags | exploit, local
SHA-256 | 09db33767583c0197cf2fc533a27f68d312a5b5a994ac463fa779980c06c0d47
wsftp402eval2.txt
Posted Mar 23, 2004
Authored by Hugh Mann

Ipswitch WS_FTP server version 4.0.2.EVAL allows a remote attacker to fill up the hard disk of the server via the REST command, resulting in a denial of service.

tags | advisory, remote, denial of service
SHA-256 | 77b6d6329d32b02f40d9fcdb072ee8f5b668c3da6d3aec7a892a5c89f8a6b227
xp_ws_ftp_server.zip
Posted Mar 23, 2004
Authored by Hugh Mann

Remote exploit for Ipswitch WS_FTP server version 4.0.2.EVAL that makes use of a buffer overflow in the STAT command.

tags | exploit, remote, overflow
SHA-256 | e993fa25947b8629ad5a12de268189a00ea40196ac545b8061e970e085a73b11
wsftp402eval.txt
Posted Mar 23, 2004
Authored by Hugh Mann

Ipswitch WS_FTP server version 4.0.2.EVAL allows for a remote user with write access to a directory the ability to execute arbitrary code due to a buffer overflow in WS_FTP Server's STAT command when downloading a file the user created.

tags | advisory, remote, overflow, arbitrary
SHA-256 | b865a821c9ab141926df964d0139b73948e886598becc6fb68a6d21a43c17b94
newsmanlite25.txt
Posted Mar 23, 2004
Authored by Manuel Lopez

News Manager Lite 2.5 and News Manager Lite administration suffer from cross site scripting, SQL injection, and cookie hijacking vulnerabilities.

tags | exploit, vulnerability, xss, sql injection
SHA-256 | c6b957877bb54eb34a118dda9d6a1ea76f8fd56c3ed84f5494f8e2553fe802e9
memmansys21.txt
Posted Mar 23, 2004
Authored by Manuel Lopez

Input validation holes in Member Management System version 2.1 allow for SQL injection and cross site scripting attacks.

tags | exploit, xss, sql injection
SHA-256 | 8843ba631656a0d022b943d1f9ed88a01141aac6cffc9a70563c08e061916c03
waraxe-2004-SA008.txt
Posted Mar 23, 2004
Authored by Janek Vind aka waraxe

PHP-Nuke versions 6.x through 7.1.0 allow for link inclusions that can force an administrator to unknowingly add a superuser.

tags | advisory, php
SHA-256 | 31cc6559f4c7a91a97c76521c220fd991009d04a5c2dbeddbe787fadbdf0b497
waraxe-2004-SA011.txt
Posted Mar 23, 2004
Authored by Janek Vind aka waraxe

MS Analysis module version 2.0 for PHP-Nuke has full path disclosure, cross site scripting, and SQL injection vulnerabilities.

tags | advisory, php, vulnerability, xss, sql injection
SHA-256 | c0010912fa273ff4a30d55b15d18fc5fd19b2b54ca1007ad349039d5a371a812
xwebTraversal10.txt
Posted Mar 22, 2004
Authored by Donato Ferrante | Site autistici.org

xweb version 1.0 is susceptible to a directory traversal attack that allows viewing of files outside of the web root.

tags | exploit, web, root
SHA-256 | 60b21d81251bb77af83e0f1e4ca6d1adf6571fe672b763de3f470ec726a71428
modsurvey0321.txt
Posted Mar 22, 2004
Authored by Niklas Deutschman

The mod_survey module versions 3.0.16-pre1 and below for Apache are susceptible to a script injection attack.

tags | advisory
SHA-256 | 18880aeaa0e51e9fe61f172cb98d6871fcde873b32f602869732da1c35fa91e9
invisionPTSL11.txt
Posted Mar 22, 2004
Authored by James Bercegay | Site gulftech.org

Invision Power Top Site List versions 1.1 and below are susceptible to a SQL injection attack.

tags | exploit, sql injection
SHA-256 | 9c7ea4878e7254176e4bcaac6f32a59ebf68c04e43e0a4b49b0efe9f6594621c
invision101PSsql.txt
Posted Mar 22, 2004
Authored by James Bercegay | Site gulftech.org

Invision Gallery version 1.0.1 fails to properly validate user supplied input allowing for various SQL injection attacks.

tags | exploit, sql injection
SHA-256 | 8406dd6fdc8e09171b80e6595a6cdc39e2810302ba082391f91b9ca2d80ba0a7
KisMACcursrc.tgz
Posted Mar 22, 2004
Authored by mick | Site kismac.binaervarianz.de

KisMAC is a stumbler application for Mac OS X that puts your card into monitor mode. Unlike most other applications for OS X, it is completely invisible and sends no probe requests.

tags | tool, wireless
systems | apple, osx
SHA-256 | 0af226cedcb727ff3b4082d3963b92f690f0a2797c3889560525a80b84ad95bb
openssh-3.8p1.tar.gz
Posted Mar 22, 2004
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: Various bug fixes.
tags | encryption
systems | linux, openbsd
SHA-256 | 4304eebd70fb7e8a565fc8bb32930abb0682b274db9fca4b50f47677bf9966b6
motiontrack-0.1.0.tar.gz
Posted Mar 21, 2004
Authored by Corvus V Corax | Site motiontrack.sourceforge.net

Motiontrack is a set of tools that detects motion between two images. It is able to successfully distinguish random flicker from real object movement by applying a set of filters to the images, and can optionally ignore given colors and/or image regions. The roadmap provides for being able to identify objects by pattern detection and AI routines. Currently, this tool is able to turn line-art images into ASCII-art text as a demo feature.

Changes: Pixel scaler added, image manipulator functions changed, base behaviour has changed.
systems | linux
SHA-256 | 796fb4c8c37c60240344f37468a047c57c32196f1c8416159e3977c0a404b5d3
phpBB207a.txt
Posted Mar 20, 2004
Authored by James Bercegay | Site gulftech.org

phpBB versions 2.0.7a and below are susceptible to cross site scripting, SQL injection, and remote command execution attacks.

tags | advisory, remote, xss, sql injection
SHA-256 | 815693b4ce058c8188efae85234c700b507656011ddae5cb4beb547eb9a22005
phpbbprofile.txt
Posted Mar 20, 2004
Authored by Cheng Peng Su

phpBB 2.0.6d suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 1253cde0d7b076a44a8d71949704b1821424924eea3d66f2ceef5e96497afdd7
xinebug.txt
Posted Mar 20, 2004
Authored by Shaun Colley aka shaun2k2

xine-bugreport suffers from insecure file creation in /tmp that can lead to a symlink attack.

tags | exploit
SHA-256 | 4fcbc54a6a9efec0d6e0816d90e344ec790ee578689ee2db652db4331f3b7d11
moddiskcache.txt
Posted Mar 20, 2004
Authored by Andreas Steinmetz

mod_disk_cache, for versions of Apache 2.0.49 and below, stores all client authentication credentials for cached objects on disk. This means proxy authentication credentials and possibly in certain RFC2616 defined cases, standard authentication credentials.

tags | advisory
SHA-256 | 33e8126715a7862594819b683f4ef3dee79a08ceed7484268d1fde2303ba2210
avscan-0.1.1.tar.bz2
Posted Mar 19, 2004
Authored by Tara Milana | Site wolfpack.twu.net

Endeavour Mark II AntiVirus Scanner is an anti-virus scanner for Endeavour Mark II that uses the ClamAV library (libclamav). It allows you to create a list of scan items for frequently scanned locations and features easy virus database updating, all in a simple GUI environment.

tags | virus
systems | unix
SHA-256 | dc9f097b7b33ffc6123308c5caffc0e5b20f5916dca866f2c6c47878f6d3cd69
fwanalog-0.6.4.tar.gz
Posted Mar 19, 2004
Authored by Balazs | Site tud.at

fwanalog is a shell script that parses and summarizes firewall logfiles. It understands logs from ipf (xBSD, Solaris), OpenBSD 3.x pf, Linux 2.2 ipchains, Linux 2.4 iptables, and a few types of routers and firewalls (Cisco, Checkpoint FW-1, and Watchguard). The excellent log analysis program Analog is used to create the reports.

Changes: Various bug fixes.
tags | tool, shell, firewall
systems | cisco, linux, unix, solaris, openbsd
SHA-256 | 8ddc4c7ec16e59a27691e25fdd1f266838230ee08c3495fa289db0e7fc008e13
apache2049.txt
Posted Mar 19, 2004
Site apache.org

Apache 2.0.49 has been released to address three security vulnerabilities. A race condition that allows for a denial of service attack, a condition that allow arbitrary strings to get written to the error log, and a memory leak in mod_ssl have all been addressed.

tags | advisory, denial of service, arbitrary, vulnerability, memory leak
advisories | CVE-2004-0174, CVE-2003-0020, CVE-2004-0113
SHA-256 | 666378a2dac755746ebe339e702406b4148bfa0f7e45b8cfb45a932c59ff3931
Page 3 of 8
Back12345Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close