what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 116 RSS Feed

Files Date: 2006-10-04 to 2006-10-05

OfficesScan-Corp.txt
Posted Oct 4, 2006
Authored by Deral Heiland | Site layereddefense.com

Layered Defense Advisory: TrendMicro OfficesScan Corporate is vulnerable to execution of arbitrary code, potential remote exploit, and denial of service.

tags | advisory, remote, denial of service, arbitrary
SHA-256 | d46d632af7507a699b201db1a7e5a3a5c7485df1d3c8ec670aa194187ccb1299
phpMyAdmin-csrf.txt
Posted Oct 4, 2006
Site hardened-php.net

Hardened-PHP Project Security Advisory: phpMyAdmin Multiple CSRF Vulnerabilities.

tags | advisory, php, vulnerability, csrf
SHA-256 | e40ffbe0958042b15dbcb1564ad43ffee9340ea266a5fee5027f3c94193e276e
FON.txt
Posted Oct 4, 2006
Authored by anonymous

Various vulnerabilities exist in the FON free wifi service.

tags | advisory, vulnerability
SHA-256 | 8ea74b8fe945edae4bd53ec05f5f387e6de5f100ff4df43b976dda7467357b51
digishopv4.0.0.txt
Posted Oct 4, 2006
Authored by meto5757

digishop v 4.0.0 suffers from a cross site scripting vulnerability

tags | advisory, xss
SHA-256 | cdb09557011c05630463a0d3455e4e19eded103ea6e2ef97f1e859bbe651687b
DayfoxBlogv2.0.txt
Posted Oct 4, 2006
Authored by Dj ReMix

Dayfox Blog v2.0 suffers from multiple instances of remote file inclusion.

tags | exploit, remote, file inclusion
SHA-256 | 2867e5bf5b3ec6d902f925b4a4e9408670f672427228ce6f5cbc7d4634c53f72
SunbeltKerio.txt
Posted Oct 4, 2006
Authored by David Matousek | Site matousec.com

Sunbelt Kerio Personal Firewall hooks many functions in SSDT and in at least six cases it fails to validate arguments that come from user mode. User calls to NtCreateFile, NtDeleteFile, NtLoadDriver, NtMapViewOfSection, NtOpenFile, NtSetInformationFile with invalid argument values can cause system crashes because of errors in Kerio drivers fwdrv.sys and khips.sys. Further impacts of this bug (like arbitrary code execution in the kernel mode) were not examined.

tags | advisory, arbitrary, kernel, code execution
SHA-256 | 48b36a564e08298f7399b3ffc2aea164592dc780e90f026e72acc165c229fee6
MS06-053.txt
Posted Oct 4, 2006
Authored by Eiji James Yoshida | Site geocities.jp

Microsoft Internet Information Services UTF-7 XSS Vulnerability

tags | advisory
SHA-256 | c8cfae828c5294e0255283416a6c2435779a4afd547fd8a52ac92dbe0906dedb
cpexploit.txt
Posted Oct 4, 2006
Authored by cp haquer

Details on exploiting the cPanel mysqladmin vulnerability which was used to circulate an IE exploit.

tags | exploit
SHA-256 | c936a8416885868de496e4242b7ed10a9d7f6e0be834330ccf44c86eff3e1eb7
phpMyWebmin1.0.txt
Posted Oct 4, 2006
Authored by XORON

phpMyWebmin 1.0 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | 675b1497b4ee8135ba73e9649cedb24dbac14222544d84c2cb02d24a7874f42a
youtube-xss.txt
Posted Oct 4, 2006
Authored by Darren Bounds

YouTube.com suffers from a cross site scripting flaw in the hidden form field "field_sendmessage_subject".

tags | advisory, xss
SHA-256 | 1fe92e0e7d355275ef0b2103ee8b3133cb508661ea26a7d4c7f338966026333c
Yblog-xss.txt
Posted Oct 4, 2006
Authored by h4ck3riran | Site Aria-security.net

Yblog suffers from a flaw that allows cross site scripting attacks.

tags | exploit, xss
SHA-256 | 69fed74c73e91009865a0a7d5d139e00ab58094177b4ecfc20ccdaf5d94d0a9c
OlateDownload3.4.0.txt
Posted Oct 4, 2006
Authored by Hessam-x | Site olate.co.uk

OlateDownload 3.4.0 suffers from SQL injection and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, sql injection
SHA-256 | d904f2cba172d62aa09051d46ea310ad95bcffdcd1e4a17729913a15f56e85fd
Owl0.82.txt
Posted Oct 4, 2006
Authored by Drago84

Owl 0.82 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | f9abbf8e402b2c4bf9b444f5d4adbd1d9f8845012f3e2a44a0870512fecbe1fe
Ptl0.2.2.txt
Posted Oct 4, 2006
Authored by Drago84

Ptl 0.2.2 suffers from a flaw that allows for local file inclusion.

tags | exploit, local, file inclusion
SHA-256 | 006e8b1660545bb5990971e26796441553e6102691cde3cee204cfa4fede2e61
phpBBXS-0.58.txt
Posted Oct 4, 2006
Authored by XORON

phpBB XS versions 0.58 and prior suffer from a remote file inclusion vulnerability.

tags | exploit, remote, file inclusion
SHA-256 | cb6536e203f267f9d431732e0e902a8fb8e5df190b646e0ca52384ae52ae053d
MacOSXMach.txt
Posted Oct 4, 2006
Authored by Matasano Advisories | Site matasano.com

MacOS X uses Mach exception ports to support the CrashReporter "Application Quit Unexpectedly" dialog, Problem Report dialog, process debugging, and crash dumps logs. On vulnerable operating systems, attackers can exploit the inheritance of Mach exception ports to inject code into SUID processes, allowing nonprivileged users to assume root privileges.

tags | advisory, root
SHA-256 | dc66c3b51c7c773705b18a72b7dc45d7174745dd453351257fb8bce4ed678bf6
MU Security Advisory 2006-09.01
Posted Oct 4, 2006
Authored by MU Dynamics | Site labs.musecurity.com

Mu Security Advisory: Multiple Pre-Authentication Vulnerabilities in MailEnable SMTP [MU-200609-01]

tags | advisory, vulnerability
SHA-256 | f16c24e6e5e0894662a9bc5a294d4f5854f06b80208788c3261aef62da2517b7
rPSA-2006-0176-1.txt
Posted Oct 4, 2006
Site rpath.com

rPath Security Advisory: 2006-0176-1: Previous versions of the openldap package contain a slapd daemon which allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN), a privilege escalation vulnerability.

tags | advisory, remote, arbitrary
SHA-256 | 722923d68306f381aa03c7d0853269d27354c3cde93946aef564de4f116a3cc7
rPSA-2006-0175-2.txt
Posted Oct 4, 2006
Site rpath.com

rPath Security Advisory: 2006-0175-2 Previous versions of the openssl package are vulnerable to multiple attacks. Three of the vulnerabilities are denials of service, but the other is a buffer overflow that is expected to create remote unauthorized access vulnerabilities in other applications. In particular, any connection that the mysql daemon will accept may be vulnerable. In the default configuration of mysql, that would be a local unauthorized access vulnerability, but mysql can be configured to listen for network connections from remote hosts, which would then enable remote unauthorized access. Any program that calls the SSL_get_shared_ciphers() function may be vulnerable.

tags | advisory, remote, overflow, local, vulnerability
SHA-256 | 7402f00d579205e017edf9cc897a11b998a2fe9bea70b4c083cf64130422668a
SiteScope8.2.txt
Posted Oct 4, 2006
Authored by ozkan.aziz | Site Whitehat.org.uk

SiteScope 8.2 (8.1.2.0) suffers from a flaw that can allow an attacker to conduct cross site scripting attacks.

tags | advisory, xss
SHA-256 | f29198f8303614abb10ec7a678bbdf818c2de6c4f125f466b953609741eabe51
JS_SearchQueryTheft.pdf
Posted Oct 4, 2006
Authored by Billy Hoffman | Site spidynamics.com

SPI Labs has discovered a practical method of using JavaScript to detect the search queries a user has entered into arbitrary search engines. All the code needed to steal a user's search queries is written in JavaScript and uses Cascading Style Sheets (CSS). This code could be embedded into any website either by the website owner or by a malicious third party through a Cross-site Scripting (XSS) attack. There it would harvest information about every visitor to that site.

tags | paper, web, arbitrary, javascript, xss
SHA-256 | ab08229f9a6ea3fe80e91cf97309e02f0a0606aa8ea3b1985c6e81d4195f426e
Trustix Secure Linux Security Advisory 2006.54
Posted Oct 4, 2006
Authored by Trustix | Site http.trustix.org

Trustix Secure Linux Security Advisory #2006-0054: Multiple vulnerabilities in openssh and openssl.

tags | advisory, vulnerability
systems | linux
SHA-256 | 7d7fccf68d4f98ce4b1d6f727cef7189498e02814248bb5a5085d6f58e0dc3bd
JoomlaBSQ.txt
Posted Oct 4, 2006
Site secunia.com

Secunia Research 29/09/2006: Joomla BSQ Sitestats Component Multiple Vulnerabilities

tags | advisory, vulnerability
SHA-256 | 4a10945e4b4e9c7ffb405280f105d7ebec08db3cf1d6ddfb45bebb717ef31faa
FreeBSD Security Advisory 2006.23
Posted Oct 4, 2006
Authored by The FreeBSD Project | Site security.FreeBSD.org

FreeBSD Security Advisory: Multiple problems in crypto(3) [revised]

tags | cryptography
systems | freebsd
SHA-256 | cf24f2e129bca457df67226f2da481a6cd4cd412bc1dd50076f6b090a5725090
ConPresso-4.0.4a.txt
Posted Oct 4, 2006
Authored by David Vieira-Kurz | Site majorsecurity.de

ConPresso CMS versions 4.0.4a and prior suffer from multiple cross site scripting and SQL injection flaws.

tags | advisory, xss, sql injection
SHA-256 | c41d3db8636e9f32928cd4ab0d505bdb2230d139acb0a530b82ed3b855c026b1
Page 2 of 5
Back12345Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close