exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 59 RSS Feed

Files Date: 2009-01-12 to 2009-01-13

25 dMx READY Products Database Disclosure
Posted Jan 12, 2009
Authored by Cyber-Zone | Site iq-ty.com

25 products from dMx READY all suffer from a remote database disclose vulnerability. Version 1.1 of Testimonials Manager, Site Engine Manager, Secure Login Manager, Secure Document Library, Registration Manager, Portfolio Manager, Polling Booth Manager, Photo Gallery Manager, PayPal Store Manager, Online Contest Manager, News Manager, Member Directory Manager, Mailing List Manager, Account List Manager, Billboard Manager, Catalog Manager, Classified Listings Manager, Contact Us Manager, Document Library Manager, Event Listing Manager, Faqs Manager, Job Listing Manager, Landing Page Manager, and Links Manager are all affected. Members Area Manager version 1.2 is also affected. DMXReady has stated that the following release addresses this security issue.

tags | exploit, remote, info disclosure
SHA-256 | df486b4f263d494c527f0748fd3320759a556c925cc4697ca07841d882730977
PWP Wiki Processor 1-5-1 File Upload
Posted Jan 12, 2009
Authored by ahmadbady

PWP Wiki Processor 1-5-1 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell, file upload
SHA-256 | 83a7f6dac45df85481372ae895e5757e05aecbecdd7c000855ce907d244a11fa
ExcelOCX 3.2 Insecure Method
Posted Jan 12, 2009
Authored by Alfons Luja

Excel Viewer OCX version 3.2 arbitrary file download and overwrite exploit.

tags | exploit, arbitrary
SHA-256 | 21c20712b13cc0aafe8584748354985796a09c4fdd4be07e3b6c9a78fc389323
Realtor 747 Remote File Inclusion
Posted Jan 12, 2009
Authored by ahmadbady

Realtor 747 version 4.11 suffers from a remote file inclusion vulnerability in define.php.

tags | exploit, remote, php, code execution, file inclusion
SHA-256 | 54a5e488d3d8ab34894543abe228dcaf53254229ee294d037ae9da1c4bb0cef4
Gentoo Linux Security Advisory 200901-8
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-08 - Multiple vulnerabilities have been reported in Online-Bookmarks. Versions less than 0.6.28 are affected.

tags | advisory, vulnerability
systems | linux, gentoo
advisories | CVE-2004-2155, CVE-2006-6358, CVE-2006-6359
SHA-256 | 291be486814345377f4516d26b5d77146c3743894bf617849c8d7160a0b0d998
Joomla Portfol SQL Injection
Posted Jan 12, 2009
Authored by Valon Kerolli | Site itshqip.com

The Joomla Portfol component suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | e14b7f15681ede07a072d0be5cc443299f5dc13e94dfcd39b4d5bc4ccfa5701b
Debian Linux Security Advisory 1703-1
Posted Jan 12, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1703-1 - It was discovered that BIND, an implementation of the DNS protocol suite, does not properly check the result of an OpenSSL function which is used to verify DSA cryptographic signatures. As a result, incorrect DNS resource records in zones protected by DNSSEC could be accepted as genuine.

tags | advisory, protocol
systems | linux, debian
advisories | CVE-2009-0025
SHA-256 | 2870f20bb99066f6892b5f6fa5169dbaaf0c0c11caa6558bdfeb5f57ca91f20e
Wordpress WP-Forum 1.7.8 SQL Injection
Posted Jan 12, 2009
Authored by seomafia

Wordpress plugin WP-Forum version 1.7.8 suffers from a remote SQL injection vulnerability in forum_feed.php.

tags | exploit, remote, php, sql injection
SHA-256 | 59b95836af54cf323cec67e10d4a75e3ddc488f6dc3663094f1660039f189a97
Debian Linux Security Advisory 1702-1
Posted Jan 12, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1702-1 - It has been discovered that NTP, an implementation of the Network Time Protocol, does not properly check the result of an OpenSSL function for verifying cryptographic signatures, which may ultimately lead to the acceptance of unauthenticated time information. (Note that cryptographic authentication of time servers is often not enabled in the first place.)

tags | advisory, protocol
systems | linux, debian
advisories | CVE-2009-0021
SHA-256 | da30bda0f6254fc59ac6cfd41f4e732342fec33fac7d90562e8150b9449d09d3
Simple Machine Forums Destroyer 0.1
Posted Jan 12, 2009
Authored by Xianur0

Simple Machines Forum Destroyer version 0.1 that performs multiple malicious acts.

tags | cracker
SHA-256 | 571c46e28eeed37f560de46ede3b84cc7932ce975f95677b6f5e13c306ebc67c
Debian Linux Security Advisory 1701-1
Posted Jan 12, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1701-1 - It was discovered that OpenSSL does not properly verify DSA signatures on X.509 certificates due to an API misuse, potentially leading to the acceptance of incorrect X.509 certificates as genuine (CVE-2008-5077).

tags | advisory
systems | linux, debian
advisories | CVE-2008-5077
SHA-256 | 82596423956ee15a8376f75613cf4b6a394787f41372c89ee99020f4389b471c
Triologic Media Player 7 Heap Overflow
Posted Jan 12, 2009
Authored by zAx

Proof of concept heap overflow exploit for Triologic Media Player 7 that creates a malicious .m3u file.

tags | exploit, overflow, proof of concept
SHA-256 | c0bca48398cfa9030b3e7438393431fed74cf74f7f12c95159f0e54b380f83db
Whitepaper - Arp Spoofing
Posted Jan 12, 2009
Authored by Affix | Site ihack.co.uk

Short whitepaper discussing the basics of ARP spoofing.

tags | paper, spoof
SHA-256 | 56f3378dd01789a74ddf49e5ff62368ae70ce2e7c90c4aef079ee4fb53ef02b7
Whitepaper - Short Review Of Modern Vulnerability Research
Posted Jan 12, 2009
Authored by Michal Bucko | Site eleytt.com

Whitepaper entitled Short Review Of Modern Vulnerability Research.

tags | paper
SHA-256 | 50f3d7b703ae7599064134dd9771cdf630e1cfeb90294a067782e794b36e361e
Whitepaper - Anonymous Internet Navigation
Posted Jan 12, 2009
Authored by ProfEsOr X

Whitepaper discussing anonymous navigation of the Internet. Written in Spanish.

tags | paper
SHA-256 | 0b41da26eab88d13fad3fbc57615b994397df2dcf6b72b8b1ea628f55bd15e1d
Gentoo Linux Security Advisory 200901-7
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-07:02 - Multiple vulnerabilities in MPlayer may lead to the execution of arbitrary code or a Denial of Service. Versions less than 1.0_rc2_p28058-r1 are affected.

tags | advisory, denial of service, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2008-3162, CVE-2008-3827, CVE-2008-5616
SHA-256 | a0d17e5282ee3f678c9d2f0857185c3ffd590e9cd23b30ec57e917b7dd662cb4
HP Security Bulletin 2007-14.81
Posted Jan 12, 2009
Authored by Hewlett Packard | Site hp.com

HP Security Bulletin - A potential security vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to create a Denial of Service (DoS).

tags | advisory, denial of service
advisories | CVE-2007-4349
SHA-256 | c97f302cc2e1218201ba03418fa7066a3111c58abd5ae5cbf808dd294d809c85
Ubuntu Security Notice 707-1
Posted Jan 12, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-707-1 - It was discovered that CUPS didn't properly handle adding a large number of RSS subscriptions. A local user could exploit this and cause CUPS to crash, leading to a denial of service. This issue only applied to Ubuntu 7.10, 8.04 LTS and 8.10. It was discovered that CUPS did not authenticate users when adding and cancelling RSS subscriptions. An unprivileged local user could bypass intended restrictions and add a large number of RSS subscriptions. This issue only applied to Ubuntu 7.10 and 8.04 LTS. It was discovered that the PNG filter in CUPS did not properly handle certain malformed images. If a user or automated system were tricked into opening a crafted PNG image file, a remote attacker could cause a denial of service or execute arbitrary code with user privileges. In Ubuntu 7.10, 8.04 LTS, and 8.10, attackers would be isolated by the AppArmor CUPS profile. It was discovered that the example pstopdf CUPS filter created log files in an insecure way. Local users could exploit a race condition to create or overwrite files with the privileges of the user invoking the program. This issue only applied to Ubuntu 6.06 LTS, 7.10, and 8.04 LTS.

tags | advisory, remote, denial of service, arbitrary, local
systems | linux, ubuntu
advisories | CVE-2008-5183, CVE-2008-5184, CVE-2008-5286, CVE-2008-5377
SHA-256 | a74367854a58a1911ddaa489d9fd8218667d9571e9707336bebfe1ff63c0d9c3
Photobase 1.2 Local File Inclusion
Posted Jan 12, 2009
Authored by Osirys | Site y-osirys.com

Photobase version 1.2 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | da7323de95f44258f494317be4115529489d8d4e08c4dea0eaee5c57ce114b51
SyScan 09 Call For Papers
Posted Jan 12, 2009
Site syscan.org

SyScan 09 Call For Papers - The Symposium on Security for Asia Network aims to be a very different security conference from the rest of the security conferences that the information security community in Asia has come to be so familiar and frustrated with. SyScan is a non-product, non-vendor biased security conference. It is the aspiration of SyScan to congregate in Asia the best security experts in their various fields, to share their research, discovery and experience with all security enthusiasts in Asia. This year SyScan will be held in Singapore, Shanghai, Taipei, and Hong Kong.

tags | paper, conference
SHA-256 | e1ca1b1275ff1fd471ee95f39b99988e7bdb740df332b2077b9cda5d57d1a00d
Visuplay CMS SQL Injection
Posted Jan 12, 2009
Authored by Joseph Giron

Visuplay CMS suffers from a remote SQL injection vulnerability in news_article.php.

tags | exploit, remote, php, sql injection
SHA-256 | 26e8a8a80fa8c769b0fd4828b1331b5c7eb265a3cf81664e81039f5dc2f51629
Aethra Starvoice SV 1042 Password Extract
Posted Jan 12, 2009
Authored by SmoKe

The Aethra SV 1042 ADSL/VOIP router suffers from a local password retrieval vulnerability.

tags | advisory, local
SHA-256 | 976d182fc143e63de58d9115d3e6324a208d6c56c7b880013bebf560b4fa6866
Ovidentia Cross Site Scripting
Posted Jan 12, 2009
Authored by Ivan Sanchez | Site nullcode.com.ar

The Ovidentia portal generator suffers from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | f5fdff9b27486dd9e03b03a1cdd8cdd6f4d5957803430461270a1bc7755283b7
Interspire Shopping Cart Authentication Bypass
Posted Jan 12, 2009
Authored by Truong Van Tri | Site bluemoon.com.vn

Interspire Shopping Cart versions 4.0.1 and below suffer from a remote authentication bypass vulnerability.

tags | advisory, remote, bypass
SHA-256 | 94975000acca58a49393a3f3d1842b09ca8ecd7cef44b79521ff5233267014a5
Silentum Uploader 1.4.0 File Deletion
Posted Jan 12, 2009
Authored by Danny Moules | Site push55.co.uk

Silentum Upload version 1.40 remote file deletion exploit.

tags | exploit, remote
SHA-256 | 098f53a317c79b74ca7317aac3e3675febd3f9fe398fadfd2b64a316a2a6c08c
Page 1 of 3
Back123Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close