what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 16 of 16 RSS Feed

Files Date: 2008-10-20 to 2008-10-21

secunia-snmp.txt
Posted Oct 20, 2008
Authored by Dyon Balding | Site secunia.com

Secunia Research has discovered a vulnerability in HP SiteScope, which can be exploited by malicious people to conduct script insertion attacks. The SiteScope server performs agent-less monitoring of the IT infrastructure and can be configured to receive SNMP traps from devices. The status of the SNMP monitor and the content of received SNMP trap messages can be viewed in the web interface. The received SNMP messages are rendered in the context of the management interface with no filtering or sanitizing. This can be exploited to execute arbitrary HTML and script code in a user's browser session when viewing the information. HP SiteScope 9.0 build 911 is affected.

tags | advisory, web, arbitrary
advisories | CVE-2007-4350
SHA-256 | 58b64bebe88c7d9ecc454e7c44918ddfccddbea43ef2062b4fc396569b32d5d0
firegpg-cleartext.txt
Posted Oct 20, 2008
Authored by moxie

The way that FireGPG handles the user's passphrase and decrypted clear-text is not secure and may result in the compromise of secure communication or a user's private key. All versions up to 0.6 are vulnerable.

tags | advisory
SHA-256 | 239f3dce0b1ce7a509db57be9343323b2b6bb6e3a2481b6c02bd2fa7453507c2
Detecting_and_Exploiting_ActiveX_Controls.pdf
Posted Oct 20, 2008
Authored by Shahriyar Jalayeri

Whitepaper entitled Detecting and Exploiting Vulnerabilities in ActiveX Controls. Written in Farsi.

tags | paper, vulnerability, activex
SHA-256 | a55486b2ef8323dff122d471481f484a8d72623c271a349cd0b318f55b96ca82
e1070713-blindsql.txt
Posted Oct 20, 2008
Authored by __GiReX__ | Site girex.altervista.org

e107 versions 0.7.13 and below blind SQL injection exploit that makes use of usersettings.php.

tags | exploit, php, sql injection
SHA-256 | 91d59e5953dbda1d47051d52fa34775268aea3cd3c9e777e0a658d88356b363f
vivvocms-destroy.txt
Posted Oct 20, 2008
Authored by Xianur0

Vivvo CMS versions 3.4 and below remote file inclusion and multiple SQL injection destroyer exploit.

tags | exploit, remote, sql injection, file inclusion
SHA-256 | 7f9103bff4f1b432f3f562d7bed2191f08191d8b4fc2ced7bca0b212870ffbd2
yappang-lfi.txt
Posted Oct 20, 2008
Authored by Vrs-hCk

yappa-ng versions 2.3.3-beta0 and below suffer from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 6e1a955f1e80775a29ffbbe17d8f7a3ea4eedad65539bd1e2a9a972955c4333b
fastclick-rfi.txt
Posted Oct 20, 2008
Authored by NoGe

Fast Click SQL version 1.1.7 Lite suffers from a remote file inclusion vulnerability in init.php.

tags | exploit, remote, php, code execution, file inclusion
SHA-256 | 628dd1e8eb291bb5da4bf4508b7502541485abe58801366660d94042b2889d51
dart-overflow.txt
Posted Oct 20, 2008
Authored by InTeL | Site pentium-xeon.blogspot.com

Dart Communications PowerTCP FTP module remote buffer overflow exploit.

tags | exploit, remote, overflow
SHA-256 | a8f30619e45ed77a4e1ba804579b586fc63fdec41d37222e7edbcbaf695b3e0e
sadmind-root.c
Posted Oct 20, 2008
Authored by Kingcope

Solaris 9 UltraSPARC sadmind remote root exploit.

tags | exploit, remote, root
systems | solaris
SHA-256 | 17da15a62198e84d12408134e9626bdb2f2cdd5077fae263ebfa63a7bbaab5b6
cpcommerce-xss.txt
Posted Oct 20, 2008
Authored by Fabian Fingerle

cpCommerce suffers from a cross site scripting vulnerability in search.php.

tags | exploit, php, xss
advisories | CVE-2008-4121
SHA-256 | ef9b5836653513efb4328f89b13fbc77287f7433d230eaecebabf6eae85bc911
CVE-2008-4000.txt
Posted Oct 20, 2008
Authored by Amichai Shulman | Site imperva.com

PeopleTools version 8.49 suffers from a brute forcing vulnerability that bypasses the account lock-out mechanism.

tags | advisory
advisories | CVE-2008-4000
SHA-256 | 1794832b45dbd92fd22d7dfa4a7894a3017ca74fc0a57e60ed4181884fae20ed
CVE-2008-2625.txt
Posted Oct 20, 2008
Authored by Amichai Shulman | Site imperva.com

Oracle versions 8i, 9i, 10g Release 1, and 10g Release 2 suffer from an unauthenticated proxy vulnerability.

tags | advisory
advisories | CVE-2008-2625
SHA-256 | ec3cad539a775dde2997a1297f85c3d7574fae33267cd0c9794bbc00b97b00db
Mandriva Linux Security Advisory 2008-208
Posted Oct 20, 2008
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount. The updated packages have been patched to fix the issue. The fix for CVE-2008-3970 uncovered crashes in the code handling the 'allow', 'deny', and 'require' options in pam_mount-0.33, released for Mandriva Linux 2008 Spring. Also, the verification of the allowed mount options ('allow' configuration directive) was inverted in pam_mount-0.33. This update fixes these issues.

tags | advisory, local
systems | linux, mandriva
advisories | CVE-2008-3970
SHA-256 | b435f6c8b6acf0291cce622d3d8674d7f5ac6833f7f5e609ae2bd0706a775bf1
Secunia Security Advisory 32317
Posted Oct 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in RealVNC VNC Viewer, which can potentially be exploited by malicious people to compromise a user's system.

tags | advisory
SHA-256 | 719eeb9bf2897333f65a02ec263225fcae349d1568c3dcc0d7783dcb23b5ace7
Secunia Security Advisory 32324
Posted Oct 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Vivvo CMS, which can be exploited by malicious people to conduct cross-site request forgery attacks.

tags | advisory, csrf
SHA-256 | e12512176d43b52fa7f9a8b65c86cc3d2de927461884bfec591adcfc37fc343a
Secunia Security Advisory 32325
Posted Oct 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Vrs-hCk has discovered a vulnerability in yappa-ng, which can be exploited by malicious people to disclose sensitive information.

tags | advisory
SHA-256 | 12adef2c23349fc19c2f4e7d893594feeb5512ef5b3f44b6024f396e98dd39ad
Page 1 of 1
Back1Next

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close