what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 73 RSS Feed

Files Date: 2009-08-06 to 2009-08-07

Whitepaper - Getting A Shell Via LFI
Posted Aug 6, 2009
Authored by SirGod

This whitepaper discusses getting a shell via local file inclusion using the proc/self/environ method.

tags | paper, shell, local, file inclusion
SHA-256 | f44a0909a494a885dd582da411b77ae0a025e7893da8bff98c4c86167b3fbfa5
Whitepaper - TCP/IP Packet Fragmentation
Posted Aug 6, 2009
Authored by Huzeyfe ONAL

Whitepaper discussing TCP/IP fragmented packets. Written in Turkish.

tags | paper, tcp
SHA-256 | 3eb1e736de2a73f79bf58ba7e0ca79b65320e7d285e2ea8ce67a094d96db1d1d
Whitepaper - Using XFS To Create XSS From SQL Injection
Posted Aug 6, 2009
Authored by 599eme Man

This whitepaper focuses on discussing how to use the SQL XFS deviation to execute cross site scripting attacks.

tags | exploit, xss
SHA-256 | d5389cf7c67fab6b3327828f65c48169a619c6b29291a442aab792d853abc3f4
Mandriva Linux Security Advisory 2009-192
Posted Aug 6, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-192 - Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark. This update provides phpmyadmin 3.2.0.1, which is not vulnerable to this issue.

tags | advisory, remote, web, arbitrary, xss
systems | linux, mandriva
advisories | CVE-2009-2284
SHA-256 | a25bc1c9c07bd970668c91dfa4f9027d4fd9f449949fee75b5faa6affc00bd11
SUSE Security Announcement - Flash Player
Posted Aug 6, 2009
Site suse.com

SUSE Security Announcement - A specially crafted Shockwave-Flash (SWF) file could cause a buffer overflow in the flash-player plugin. This buffer overflow can probably be exploited to execute arbitrary code remotely.

tags | advisory, overflow, arbitrary
systems | linux, suse
advisories | CVE-2009-0901, CVE-2009-1862, CVE-2009-1863, CVE-2009-1864, CVE-2009-1865, CVE-2009-1866, CVE-2009-1867, CVE-2009-1868, CVE-2009-1869, CVE-2009-1870, CVE-2009-2395, CVE-2009-2493
SHA-256 | 9c145062d4387103164347ba1fdb5070b4fa232183ed065f9d873ded408caf20
Ubuntu Security Notice 811-1
Posted Aug 6, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-811-1 - Juan Pablo Lopez Yacubian discovered that Firefox did not properly display invalid URLs. If a user were tricked into accessing a malicious website, an attacker could exploit this to spoof the location bar, such as in a phishing attack. Furthermore, if the malicious website had a valid SSL certificate, Firefox would display the spoofed page as trusted.

tags | advisory, spoof
systems | linux, ubuntu
advisories | CVE-2009-2654
SHA-256 | fd214a085a63ba45443b5611745a693b150a444bf8e8a7728d48059d6966ffb6
Silurus Classifieds Cross Site Scripting
Posted Aug 6, 2009
Authored by Moudi

Silurus Classifieds suffers from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 2b2f51aaf7864a4be12de605b50a787b5647bde22df6bf8ccb60b840195f9c16
Virtue Shopping Mall SQL Injection
Posted Aug 6, 2009
Authored by Moudi

Virtue Shopping Mall suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 614d4ffc660f667c42ba5198c3e659c1fc05ca7dcd0cc2e365d4f8ea6a46a4b8
Virtue News Manager SQL Injection
Posted Aug 6, 2009
Authored by Moudi

Virtue News Manager suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 758a32c7596ffad2a73cc4859512c3cecee0e59a83d030c06418ae61b36f9824
Virtue Book Store SQL Injection
Posted Aug 6, 2009
Authored by Moudi

Virtue Book Store suffers from a remote SQL injection in detail.php.

tags | exploit, remote, php, sql injection
SHA-256 | 8a54a0758a9a0dfb6813a0f73391a0236473ae9499909f1cf0c27efb022e0daf
Palm Pre WebOS 1.0.4 HTML Injection
Posted Aug 6, 2009
Authored by Townsend Ladd Harris

Palm Pre WebOS versions 1.0.4 and below suffer from an arbitrary html injection vulnerability.

tags | exploit, arbitrary
SHA-256 | 388afe43695652de87e411d8ed175a52521f0c756bb18627debceeef7dedfaaf
Oracle Enterprise Manager SQL Injection
Posted Aug 6, 2009
Authored by Esteban Martinez Fayo | Site appsecinc.com

Team SHATTER Security Advisory - Oracle Enterprise Manager Database Control 11 (11.1.0.6, 11.1.0.7) and Oracle Enterprise Manager 10g Grid Control 10.2.0.4 (and previous patchsets) suffer from multiple SQL injection vulnerabilities.

tags | advisory, vulnerability, sql injection
advisories | CVE-2009-1966, CVE-2009-1967
SHA-256 | 1f9e8a8d70e706e7a333b2c2deb353c2994c4cfe3b579aeac098feb6ae91a71e
Tutorial On Remote / Local File Inclusion
Posted Aug 6, 2009
Authored by int_main();

This is a brief tutorial on remote and local file inclusion attacks. Written in German.

tags | paper, remote, local, file inclusion
SHA-256 | 4a3e6145d0a0a7301e5157b69be48a9913d2849e368c4a7e5d9a8eadfe0c6bcb
Whitepaper About Blind SQL Injection
Posted Aug 6, 2009
Authored by MizoZ

This is a brief write up discussing blind SQL injection attacks. Written in French.

tags | paper, sql injection
SHA-256 | 850e44ffacd06e23d7caec378232e76af6b7f4ef2eb9209c89c61b21dba24190
Whitepaper - Optimización de SQL Union Injection en MYSQL
Posted Aug 6, 2009
Authored by OzX | Site foro.undersecurity.net

Whitepaper called Optimizacion de SQL Union Injection en MYSQL. Written in Spanish.

tags | paper
SHA-256 | 89d8781420c427ea8b45be477b8596c114134e005d430eea4c74bd2273a6baef
Portel Blind SQL Injection
Posted Aug 6, 2009
Authored by Chip D3 Bi0s

Portel suffers from a blind remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | bb36f49b8c5e8c632eca711b49aa7250fceecd8b91e98f1fa5000340b9e67833
Irokez 0.7.1 SQL Injection
Posted Aug 6, 2009
Authored by Ins3t | Site arthacking.net

Irokez CMS 0.7.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | ecbf28add8c7d8e84dc281315a74e8e12f3cf3a794ec7be70594fd308bd55e23
Forum Script Cross Site Scripting
Posted Aug 6, 2009
Authored by 599eme Man

Forum Script suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a1eda262f0e2bbc874478635d8beec226eba3e0b1823e37dcc29a03b847f9041
Directory Escort Script Cross Site Scripting
Posted Aug 6, 2009
Authored by 599eme Man

Directory Escort Script suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 3f4d3e2c773b2c62067f9e1c6090bf12ddfda7cf8a08f09f639e41ce6976d5d0
Auction Website Script SQL Injection
Posted Aug 6, 2009
Authored by 599eme Man

Auction Website Script suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 5e20baa8a39daf6b81ff212b4375a837aaeb106346735a10d6f7038da35a0cc2
AJauctionPro Oopd 3.0 Cross Site Scripting
Posted Aug 6, 2009
Authored by 599eme Man

AJauctionPro Oopd version 3.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 023550e19dac3ab5bbd61fc7a7e8dfea73bffcdd64a040ef1854d29e3f9e0306
CS-Cart 2.0.5 SQL Injection
Posted Aug 6, 2009
Authored by Ryan Dewhurst

CS-Cart versions 2.0.5 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | f3932067a98b57e97ac08258f33afd7ef263341a7329fcec80132aae6b1aee04
Ubuntu Security Notice 810-2
Posted Aug 6, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-810-2 - USN-810-1 fixed vulnerabilities in NSS. This update provides the NSPR needed to use the new NSS. Original advisory details: Moxie Marlinspike discovered that NSS did not properly handle regular expressions in certificate names. A remote attacker could create a specially crafted certificate to cause a denial of service (via application crash) or execute arbitrary code as the user invoking the program. Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Dan Kaminsky discovered NSS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site.

tags | advisory, remote, denial of service, arbitrary, vulnerability
systems | linux, ubuntu
SHA-256 | 141dc865e1cc92a69424274d23598cd30ffe65f83e74c1fb4dd4182ff17a9887
Ubuntu Security Notice 810-1
Posted Aug 6, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-810-1 - Moxie Marlinspike discovered that NSS did not properly handle regular expressions in certificate names. A remote attacker could create a specially crafted certificate to cause a denial of service (via application crash) or execute arbitrary code as the user invoking the program. Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Dan Kaminsky discovered NSS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2009-2404, CVE-2009-2408, CVE-2009-2409
SHA-256 | 551f75cb720ebd7eaa1e942d3bd0085543b035e372926a826f94e7e0b94f1eb5
In-Portal 4.3.1 Local File Inclusion
Posted Aug 6, 2009
Authored by Securitylab Security Research | Site securitylab.ir

In-Portal version 4.3.1 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | ee05a4c24b9d21334fd46c599e895ffa41d734a9e76825baf4cf1bc0054d43ec
Page 2 of 3
Back123Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close