exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 59 RSS Feed

Files Date: 2009-01-12 to 2009-01-13

Comersus Shopping Cart Password Exploit
Posted Jan 12, 2009
Authored by ajann

Comersus Shopping Cart versions 6 and below remote user password exploit.

tags | exploit, remote
SHA-256 | 85811285b1b4093109d8e4e05f1be5765126afdb74df6e742c9f6c53bb7dd482
Netgear WG102 SNMP Password Leak
Posted Jan 12, 2009
Authored by Harm S.I. Vaittes

The Netgear WG102 has the SNMP write community (password) accessible in cleartext via the MIB which is readable via the SNMP read community.

tags | exploit
SHA-256 | 3c51a78420a0df8febc79c022317d8f0c0dc20bcc300e24c5d2b80e393e67407
Amarok Integer Overflow / Unchecked Allocation Vulnerabilities
Posted Jan 12, 2009
Authored by Tobias Klein | Site trapkit.de

Amarok contains several integer overflows and unchecked allocation vulnerabilities while parsing malformed audible digital audio files. The vulnerabilities may be exploited by a (remote) attacker to execute arbitrary code in the context of Amarok.

tags | advisory, remote, overflow, arbitrary, vulnerability
SHA-256 | b94ef4ce7d1b2e477a85e81fe7d6abeaf756a2d58b5544818985f2c20cb90bb6
Sun Solaris aio_suspend() Kernel Integer Overflow
Posted Jan 12, 2009
Authored by Tobias Klein | Site trapkit.de

Sun Solaris suffers from an aio_suspend() kernel integer overflow vulnerability.

tags | advisory, overflow, kernel
systems | solaris
SHA-256 | cf4e53dd00147f6634c2f3e122968aec17988d62f758b49a1e1ca73472516ca8
BKWorks ProPHP 0.50b1 SQL Injection
Posted Jan 12, 2009
Authored by SirGod | Site insecurity.ro

BKWorks ProPHP version 0.50b1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | b6bbb0e66ae2e75ec0215b724b061c743b547b2f5011beb78fdfca6831296b80
Xplico Network Forensics Analysis Tool 0.1
Posted Jan 12, 2009
Authored by Gianluca Costa, Andrea de Franceschi | Site xplico.org

Xplico is an open source Network Forensic Analysis Tool (NFAT) that allows for data extraction from traffic captures. It supports extraction of mail from POP, IMAP, and SMTP, can extract VoIP streams, etc.

Changes: Added the IMAP dissector.
tags | tool, imap, forensics
SHA-256 | 2c7281e26af9f4375f1fba80d772b37b730c87d38141e6995bc2ead45f2ef103
Gentoo Linux Security Advisory 200901-6
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-06 - A buffer overflow vulnerability has been discovered in Tremulous. It has been reported that Tremulous includes a vulnerable version of the ioQuake3 engine (GLSA 200605-12, CVE-2006-2236). Versions less than 1.1.0-r2 are affected.

tags | advisory, overflow
systems | linux, gentoo
advisories | CVE-2006-2236
SHA-256 | 283ce7d4a6859f05b0f7055117edc77e5200ad422ef1eb33032e181fc0156290
Gentoo Linux Security Advisory 200901-5
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-05 - Multiple buffer overflows have been discovered in Streamripper, allowing for user-assisted execution of arbitrary code. Stefan Cornelius from Secunia Research reported multiple buffer overflows in the http_parse_sc_header(), http_get_pls() and http_get_m3u() functions in lib/http.c when parsing overly long HTTP headers, or pls and m3u playlists with overly long entries. Versions less than 1.64.0 are affected.

tags | advisory, web, overflow, arbitrary
systems | linux, gentoo
advisories | CVE-2008-4829
SHA-256 | 06710cdf85609b49b9e02c8b791e5ed9458ce96767d0fc3900a9ba20f466791e
Gentoo Linux Security Advisory 200901-4
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-04 - An error condition can cause D-Bus to crash. schelte reported that the dbus_signature_validate() function can trigger a failed assertion when processing a message containing a malformed signature. Versions less than 1.2.3-r1 are affected.

tags | advisory
systems | linux, gentoo
advisories | CVE-2008-3834
SHA-256 | e86dda15dbd223756769eb5a6cb0db3ff174fdfad0f95fb3aed50a8d3969a8c4
Gentoo Linux Security Advisory 200901-3
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-03 - Two errors in pdnsd allow for Denial of Service and cache poisoning. Versions less than 1.2.7 are affected.

tags | advisory, denial of service
systems | linux, gentoo
advisories | CVE-2008-1447, CVE-2008-4194
SHA-256 | 4b5ce9962aef3dfe259bf205679bc9936d66a6ddc9dacad36e520a30b4d74ece
Gentoo Linux Security Advisory 200901-2
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-02 - Multiple vulnerabilities in JHead might lead to the execution of arbitrary code or data loss. Versions less than 2.84-r1 are affected.

tags | advisory, arbitrary, vulnerability
systems | linux, gentoo
advisories | CVE-2008-4575, CVE-2008-4639, CVE-2008-4640, CVE-2008-4641
SHA-256 | 69352640345ae81ab7981ab3b11c54588fc1cefd02630aad6d89b1768afc9683
Gentoo Linux Security Advisory 200901-1
Posted Jan 12, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200901-01 - Multiple buffer overflows might lead to remote execution of arbitrary code with root privileges. Anders Kaseorg reported multiple buffer overflows related to long ESSIDs. Versions less than 1.53-r1 are affected.

tags | advisory, remote, overflow, arbitrary, root
systems | linux, gentoo
advisories | CVE-2008-4395
SHA-256 | 87b26f86c4dbef558e268f86b44703fd0b09ecee788d360dbf8898c733914faf
Fast Guest Book SQL Injection
Posted Jan 12, 2009
Authored by Moudi

Fast Guest Book suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | 14c3690ed933bc52831e5ab1f0ff2a9092eea09d9f5ec96d3a9f52e6c125b408
Weight Loss Recipe Book 3.1 SQL Injection
Posted Jan 12, 2009
Authored by X0r

Weight Loss Recipe Book versions 3.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | 78b9d5e916666145255e4d539942673293977d62dfe3c79de13e8b3593f33e4b
DZcms 3.1 SQL Injection
Posted Jan 12, 2009
Authored by Glafkos Charalambous | Site astalavista.com

DZcms version 3.1 suffers from a remote SQL injection vulnerability in products.php.

tags | exploit, remote, php, sql injection
SHA-256 | 3625a663d32f09d2bbaeb82eb5bf7087c73519bd5a02e5b64a62410ad0443e82
Debian Linux Security Advisory 1700-1
Posted Jan 12, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1700-1 - It was discovered that Lasso, a library for Liberty Alliance and SAML protocols performs incorrect validation of the return value of OpenSSL's DSA_verify() function.

tags | advisory, protocol
systems | linux, debian
advisories | CVE-2009-0050
SHA-256 | 48e98cae2f44369a048191e19c766e168a60c960f19a7195602408e8f45b9e5f
Debian Linux Security Advisory 1699-1
Posted Jan 12, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1699-1 - An array index error in zaptel, a set of drivers for telephony hardware, could allow users to crash the system or escalate their privileges by overwriting kernel memory.

tags | advisory, kernel
systems | linux, debian
advisories | CVE-2008-5396, CVE-2008-5744
SHA-256 | 41809d3fbd0f8ef9ec0b5f913140c8648d4d4ef0f00416c132443f96bf9575bd
fttss 2.0 Command Execution
Posted Jan 12, 2009
Authored by dun

fttss versions 2.0 and below suffer from a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | f9dceb86f7d799e014489962bfe0f7f4d9c1b8bcd5b27aa4bed6d2986270c8dd
Scoail Engine SQL Injection
Posted Jan 12, 2009
Authored by Snakespc | Site snakespc.com

Social Engine suffers from a remote SQL injection vulnerability in browse_classifieds.php.

tags | exploit, remote, php, sql injection
SHA-256 | df900bc6ceba5c468fe4b4a16a21fc2e62a64a2c8620a293c827ded68872628b
PHP 5.2.8 popen Overflow
Posted Jan 12, 2009
Authored by e.wiZz!

Proof of concept code that causes Apache version 2.2.11 to crash when leveraging a buffer overflow found in popen from PHP version 5.2.8.

tags | exploit, overflow, php, proof of concept
SHA-256 | 69cd17b5829ffa6527992c1503dcd45d99c32941edab0451a004965ef6fad5fc
PHP-Fusion the_kroax SQL Injection
Posted Jan 12, 2009
Authored by FasTWORM | Site cyber-warrior.org

The PHP-Fusion module the_kroax suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
SHA-256 | 52126f916308a0ef7fd3781c9acdbcc830556847649522a62aef59dd1e0dca06
phpMDJ 1.0.3 Blind SQL Injection
Posted Jan 12, 2009
Authored by darkjoker | Site darkjokerside.altervista.org

phpMDJ versions 1.0.3 and below remote blind SQL injection exploit.

tags | exploit, remote, sql injection
SHA-256 | 71043bfd3e8f83fc8a1b7f4929e7c082135abd42023ca0557440c555c3e2a6f6
Mandriva Linux Security Advisory 2009-005
Posted Jan 12, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-005 - A vulnerability has been discovered in xterm, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to xterm not properly processing the DECRQSS Device Control Request Status String escape sequence. This can be exploited to inject and execute arbitrary shell commands by e.g. tricking a user into displaying a malicious text file containing a specially crafted escape sequence via the more command in xterm. The updated packages have been patched to prevent this.

tags | advisory, arbitrary, shell
systems | linux, mandriva
advisories | CVE-2008-2383
SHA-256 | 2493748ea4d2a9b36180e68cee133d311ce65680b96da22fdf380057be4be1d0
Mandriva Linux Security Advisory 2009-004
Posted Jan 12, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-004 - passwdehd script in pam_mount would allow local users to overwrite arbitrary files via a symlink attack on a temporary file. The updated packages have been patched to prevent this.

tags | advisory, arbitrary, local
systems | linux, mandriva
advisories | CVE-2008-5138
SHA-256 | 995db9d8e704d137acc94adf36b40d3c21069603dadd49461a20f850d20d6687
Mandriva Linux Security Advisory 2009-003
Posted Jan 12, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-003 - Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer overflow. Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c. The updated Python packages have been patched to correct these issues.

tags | advisory, overflow, arbitrary, python
systems | linux, mandriva
advisories | CVE-2008-4864, CVE-2008-5031
SHA-256 | 28d63a5f76ce1c5a97ac6618dfcd9bf320b89e89ddb038a765988adc6e0b6471
Page 2 of 3
Back123Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close