what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 72 RSS Feed

Files Date: 2009-07-17 to 2009-07-18

Ger Versluis 2000 SQL Injection
Posted Jul 17, 2009
Authored by DeCo017

Ger Versluis 2000 version 5.5 24 suffers from a remote SQL injection vulnerability in SITE_fiche.php.

tags | exploit, remote, php, sql injection
SHA-256 | f1bd591c48448148fd348f7f0227644059f1c2c6a4306824267783b2e6a8d331
Battle Blog 1.25 SQL Injection / Authentication Bypass
Posted Jul 17, 2009
Authored by SqL_DoCt0r

Battle Blog version 1.25 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | faaa6c0707364c1b20aec7895084419f30188ae1662bbdfefe1345f0773ca028
Super Simple Blog Script 2.5.4 SQL Injection
Posted Jul 17, 2009
Authored by jiko

Super Simple Blog Script version 2.5.4 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 2eaf78f0259db4226e81b5847645bc8773165a6abee749b4d5675396c8055510
AJOX Poll Authentication Bypass
Posted Jul 17, 2009
Authored by SirGod | Site insecurity.ro

AJOX Poll suffers from an authentication bypass vulnerability.

tags | exploit, bypass
SHA-256 | 468b81bb47c7541464a43fee4a02f03bcd6be3130560edff0cb36970890793b7
Sniffing SAP GUI Passwords
Posted Jul 17, 2009
Authored by Andreas Baus, Rene Ledosquet

This paper describes a practical attack against the protocol used by SAP for client server communication. The purpose of this paper is to clarify the fact that the protocol does not sufficiently protect sensitive information like user names and passwords.

tags | paper, protocol
SHA-256 | f6435814e3afad6ebb4262a9c614cacd418277717cf925da94343a17ae06aa57
Gentoo Linux Security Advisory 200907-14
Posted Jul 17, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200907-14 - A directory traversal vulnerability in Rasterbar libtorrent might allow a remote attacker to overwrite arbitrary files. census reported a directory traversal vulnerability in src/torrent_info.cpp that can be triggered via .torrent files. Versions less than 0.13-r1 are affected.

tags | advisory, remote, arbitrary
systems | linux, gentoo
advisories | CVE-2009-1760
SHA-256 | 2e799ebd355637e542c267e8331df9e50b6992123a5c166740bf71f8ea5e2b8e
Super Simple Blog Script 2.5.4 Local File Inclusion
Posted Jul 17, 2009
Authored by jiko

Super Simple Blog Script version 2.5.4 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 366768ae70b606de0d7bb00223af59b1fc919d438c466bf9f3b0ee254fcbc30d
PHPLive 3.2.1/2 Blind SQL Injection
Posted Jul 17, 2009
Authored by boom3rang | Site khq-crew.ws

PHPLive versions 3.2.1 and 3.2.2 suffer from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 19f6ac6b2c16407931d51161f7b1340078dfbd0f6f21782112ec19793cd93b2c
VS Panel 7.5.5 SQL Injection
Posted Jul 17, 2009
Authored by C0D3R-Dz

VS Panel version 7.5.5 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7839ca6fc4dba932d7af30ad329307b23f38f2a2d632705ad899c57b60423e56
Linux 2.6.30+/SELinux/RHEL5 Local Root Exploit
Posted Jul 17, 2009
Authored by Brad Spengler

Linux 2.6.30+/SELinux/RHEL5 local root exploit. Works on both 32bit and 64bit kernels.

tags | exploit, kernel, local, root
systems | linux
SHA-256 | 3709a659201e1e4914bcbd137c9f08224a39b712f0e57cf22a9cbec5957de619
Ubuntu Security Notice 804-1
Posted Jul 17, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-804-1 - Tavis Ormandy and Yorick Koster discovered that PulseAudio did not safely re-execute itself. A local attacker could exploit this to gain root privileges.

tags | advisory, local, root
systems | linux, ubuntu
advisories | CVE-2009-1894
SHA-256 | b8beb3fe604ec782db3bd384c85199c455906f54b4b92e94931ef02d23954d69
American Airlines Local File Inclusion
Posted Jul 17, 2009
Authored by Bob Smith

American Airlines' sites suffer from a local file inclusion vulnerability. The author was ignored when contacting them so this is being published.

tags | exploit, local, file inclusion
SHA-256 | fda78076c0e5b1cc9ca87be6898c56ce10b32556cded3690d40d24dba883f27e
ZenPhoto Gallery 1.2.5 Password Reset
Posted Jul 17, 2009
Authored by petros

ZenPhoto Gallery version 1.2.5 administrator password reset exploit using cross site request forgery.

tags | exploit, csrf
SHA-256 | 1a2d15c4041d20cefe60ca298054f060cd86c3a57e3568f9c13a0d676329c67b
Oracle BEA Weblogic 10 XSS
Posted Jul 17, 2009
Authored by Sh2kerr | Site dsecrg.com

Oracle BEA Weblogic version 10.3 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 9a650695810614f4973ffb7f573662e9896423657f31d2bd9a505ef52184447a
Oracle Secure Enterprise Search XSS
Posted Jul 17, 2009
Authored by Sh2kerr | Site dsecrg.com

Oracle Secure Enterprise Search (SES) version 10.1.8.2.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2009-1968
SHA-256 | 94834e7f4609e3dadfba3ea1aae38f276c43166e3d130a1e1273d767615609e3
Open Source CERT Security Advisory 2009.11
Posted Jul 17, 2009
Authored by Andrea Barisani, Open Source CERT | Site ocert.org

Android, an open source mobile phone platform, improperly checks permissions when applications access the camera and audio resources. All 1.5 GRBxx versions are affected.

tags | advisory
advisories | CVE-2009-2348
SHA-256 | 4b7c6f448acecc2ccbd344ea7c61afdac0b498f3432e5044a92d1cb41fd80890
WebLeague 2.2.0 SQL Injection / Authentication Bypass
Posted Jul 17, 2009
Authored by ka0x

WebLeague version 2.2.0 remote SQL injection exploit that performs authentication bypass.

tags | exploit, remote, sql injection, bypass
SHA-256 | 56b80450b2e49f96bb4663e79307fcd502f54b0769bdafc927f32604532ca8de
WebLeague 2.2.0 Password Changer
Posted Jul 17, 2009
Authored by TiGeR-Dz | Site h4ckf0u.com

WebLeague version 2.2.0 remote change password exploit that leverages install.php.

tags | exploit, remote, php
SHA-256 | 3fb5da098010897a942a82ef5b38853ffffb816299b2b2dcd1eaab4ba881e30f
WebLeague 2.2.0 SQL Injection
Posted Jul 17, 2009
Authored by Arka69

WebLeague version 2.2.0 suffers from a remote SQL injection vulnerability in profile.php.

tags | exploit, remote, php, sql injection
SHA-256 | 31375ea467033249c5fefe4dcfc75e0793b59e42aba3f44914bbbb9f5d6ebb4b
Infinity 2.0.5 Create Admin Exploit
Posted Jul 17, 2009
Authored by Qabandi

Infinity versions 2.0.5 and below arbitrary create administrator exploit.

tags | exploit, arbitrary, add administrator
SHA-256 | 1474e48bd198bb26943a78a4ab23baca7ad396e18632ca7d374d013fcce3e1b5
Haraldscan Bluetooth Discovery Scanner
Posted Jul 17, 2009
Authored by Terence Stenvold | Site code.google.com

Harald Scan is a Bluetooth discovery scanner. It determines Major and Minor device classes according to the Bluetooth SIG specification and attempts to resolve a device's MAC address to the largest known vendor/MAC address list. Written in Python.

Changes: Added a CLI argument to always do a service scan. 205 MACLIST entries.
tags | tool, python, wireless
SHA-256 | a2dd70511dc23d8b1a5e3c9c0c58ad172b1d2b69b541733b29c44ff752626bbe
Gentoo Linux Security Advisory 200907-13
Posted Jul 17, 2009
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200907-13 - A vulnerability in PulseAudio may allow a local user to execute code with escalated privileges. Tavis Ormandy and Julien Tinnes of the Google Security Team discovered that the pulseaudio binary is installed setuid root, and does not drop privileges before re-executing itself. The vulnerability has independently been reported to oCERT by Yorick Koster. Versions less than 0.9.9-r54 are affected.

tags | advisory, local, root
systems | linux, gentoo
advisories | CVE-2009-1894
SHA-256 | 0845b919b201ac150850dea798592c3e2d37064dc4f6d888379d713a2eda6d3d
Debian Linux Security Advisory 1836-1
Posted Jul 17, 2009
Authored by Debian | Site debian.org

Debian Security Advisory 1836-1 - Vinny Guido discovered that multiple input sanitising vulnerabilities in Fckeditor, a rich text web editor component, may lead to the execution of arbitrary code.

tags | advisory, web, arbitrary, vulnerability
systems | linux, debian
advisories | CVE-2009-2265
SHA-256 | 8aca73d4db5e9a83ca752db9f342ac157518676f56efb95cb2c291cfe066ef03
OnePound Shop 1.x SQL Injection / XSS
Posted Jul 17, 2009
Authored by NoGe

OnePound Shop version 1.x suffers from blind SQL injection and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, sql injection
SHA-256 | f02ec4164088a06aa297e0f32460d74139b7180ff68c5f86d50a6be94eea8f03
Audio Editor Pro 2.91 Memory Corruption
Posted Jul 17, 2009
Authored by LiquidWorm | Site zeroscience.mk

Audio Editor Pro version 2.91 suffers from a memory corruption vulnerability.

tags | advisory
SHA-256 | 64622995076d75dbace9f66f378ed9f87ac2c88ce07f202f1987657ee9ec774e
Page 2 of 3
Back123Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close