what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 76 RSS Feed

Files Date: 2010-01-07 to 2010-01-08

Ubuntu Security Notice 880-1
Posted Jan 7, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 880-1 - Stefan Cornelius discovered that GIMP did not correctly handle certain malformed BMP files. If a user were tricked into opening a specially crafted BMP file, an attacker could execute arbitrary code with the user's privileges. Stefan Cornelius discovered that GIMP did not correctly handle certain malformed PSD files. If a user were tricked into opening a specially crafted PSD file, an attacker could execute arbitrary code with the user's privileges. This issue only applied to Ubuntu 8.10, 9.04 and 9.10.

tags | advisory, arbitrary
systems | linux, ubuntu
advisories | CVE-2009-1570, CVE-2009-3909
SHA-256 | abfaff4f2057c4885200056001e88d026401c3e2ef40fbfc793fe89e6662298f
Built By Kleber 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by PaL-D3v1L

Built By Kleber version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ccb5be5138b166e0e759f455edef576a28d48f29c01360ae02a1468d446526c0
Lone Peak Video Productions 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by PaL-D3v1L

Lone Peak Video Productions version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ef1452343f29127cc5613b09b9851c034b4fc9d54a5ab4663aea921197a7af4b
markItUp 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by R3d-D3v!L

markItUp version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 6782ba384c4f8ad40d1897eaecffc7b56713a9239ceec34c797e9d6014150d2e
Zeeways Technology SQL Injection
Posted Jan 7, 2010
Authored by Gamoscu

Zeeways Technology suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7ee6b5219624f51cdc93e753aa1d07fdf4e0eb1a8f00cdb6a3e29bdda35d49a1
VMWare Insecure Permissions
Posted Jan 7, 2010
Authored by dd

It appears that the VMWare server installer may fail to set the umask and/or file permissions upon installation.

tags | advisory
SHA-256 | ab3baa2673ce5d2da033a24d3862de9f64c2ea0e93bffed05160a6e08193f759
HP OmniInet.exe MSG_PROTOCOL Buffer Overflow
Posted Jan 7, 2010
Authored by EgiX, jduck, riaf | Site metasploit.com

This Metasploit module exploits a stack-based buffer overflow in the Hewlett-Packard OmniInet NT Service. By sending a specially crafted MSG_PROTOCOL (0x010b) packet, a remote attacker may be able to execute arbitrary code with elevated privileges. This service is installed with HP OpenView Data Protector, HP Application Recovery Manager and potentially other products. This exploit has been tested against versions 6.1, 6.0, and 5.50 of Data Protector. and versions 6.0 and 6.1 of Application Recovery Manager. NOTE: There are actually two consecutive wcscpy() calls in the program (which may be why ZDI considered them two separate issues). However, this module only exploits the first one.

tags | exploit, remote, overflow, arbitrary
advisories | CVE-2007-2280
SHA-256 | 098a37312c7769272d53b6747df73473c2997a18bf5130110137953613125b72
HP OmniInet.exe MSG_PROTOCOL Buffer Overflow
Posted Jan 7, 2010
Authored by EgiX, jduck, riaf | Site metasploit.com

This Metasploit module exploits a stack-based buffer overflow in the Hewlett-Packard OmniInet NT Service. By sending a specially crafted MSG_PROTOCOL (0x010b) packet, a remote attacker may be able to execute arbitrary code with elevated privileges. This service is installed with HP OpenView Data Protector, HP Application Recovery Manager and potentially other products. This exploit has been tested against versions 6.1, 6.0, and 5.50 of Data Protector. and versions 6.0 and 6.1 of Application Recovery Manager. NOTE: There are actually two consecutive wcscpy() calls in the program (which may be why ZDI considered them two separate issues). However, this module only exploits the second one.

tags | exploit, remote, overflow, arbitrary
advisories | CVE-2009-3844
SHA-256 | 6077abc4561b8bb88f893fcbc753edd3a1b15ac32e3ac4ebcdc7446ce7360c3c
Sniggabo CMS 2.21 Cross Site Scripting
Posted Jan 7, 2010
Authored by Sora

Sniggabo CMS version 2.21 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a892685595e5f19d5ff6f696e8d2e2479ef09161f35bd8df02752fcda68b3dfa
Ulisse's Scripts 2.6.1 SQL Injection
Posted Jan 7, 2010
Authored by Sora

Ulisse's Scripts version 2.6.1 suffers from a remote SQL injection vulnerability in ladder.php.

tags | exploit, remote, php, sql injection
SHA-256 | 3662f1abb30ab7a3dc33f968583b82391eeefb84830ffb52acf94002a3582c9d
ellistonSPORT SQL Injection
Posted Jan 7, 2010
Authored by NoGe

ellistonSPORT suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 13e1b8534d82676f67d1d881b82b25b503fb59f7f4619cdbde6e376ac03126e5
Hispanic Digital Network SQL Injection
Posted Jan 7, 2010
Authored by NoGe

Hispanic Digital Network suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 82dbb2ee981c637f1c517f45b22289d648a06591842e65e6e0ea1d698e3d73f8
Joomla DM Orders SQL Injection
Posted Jan 7, 2010
Authored by NoGe

The Joomla DM Orders component suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | acca147ab28795cbeed1eb35d6ef1dcbfc3689fbbafd4efd78d302216e31ad0b
SpawCMS Shell Upload
Posted Jan 7, 2010
Authored by j4ck

SpawCMS suffers from a shell upload vulnerability.

tags | exploit, shell
SHA-256 | 5d11cbad7b08f0061a826ff274da19fa79b384f4fc27e6e32d27acb2a65fcca3
Cricinfo Games 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by R3d-D3v!L

Cricinfo Games version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ff0b3d6735f644db3178df500e56d7500b4fefc1a40fe8529de8320b62ee759c
Delta Duo Script 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by R3d-D3v!L

Delta Duo Script version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a6a04728ca06d0e2aece5a2b6b8e6d128dd9842237e5c77ff13ef29bec220ba4
Cb0ne Script 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by R3d-D3v!L

Cb0ne Script version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ee3b83d1b6b35f8c12a53f5a7c77b5e674da59a0e58dae988af4bfcb039af7a5
SAMPLE Lord 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by R3d-D3v!L

SAMPLE Lord version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | d8126e56a829049763953c2d609590352eac1ab2d647a107b5777f1503e738c2
RoundCubeWebmail 0.2.x Cross Site Scripting
Posted Jan 7, 2010
Authored by Globus, j4ck

RoundCubeWebmail version 0.2.x suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 70e53fadb4f32dad69a12c8f085a7e51f55611388a5bfa6d594450da6c1951ad
Mediatraffic Script 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by R3d-D3v!L

Mediatraffic Script version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | b2b8cdb3a59912d6d95ead62447045b4c5625bfcf7b27b35eea990e2feb7afe8
PNG Counter 1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by R3d-D3v!L

PNG Counter version 1.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | e407ae479e0e25afa26ad0d8bea8d8947fed83310ba6fb08dc814deee8d0804f
SafeCms 2.0.1.0 Cross Site Scripting
Posted Jan 7, 2010
Authored by cp77fk4r

SafeCms versions 2.0.1.0 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | b95e985781f00b2d025644d8d5581fd4e7d7de144c6af3b2a0a3f9864f5f6339
Microsoft HTML Help Compiler Buffer Overflow
Posted Jan 7, 2010
Authored by sasquatch

Microsoft HTML Help Compiler buffer overflow proof of concept exploit.

tags | exploit, overflow, proof of concept
SHA-256 | e9fe9605397f9e68a7d203465bd5bc79da2294df71a4fb6b38f8e3f4676da78b
Novell eDirectory 8.8 SP5 Buffer Overflow
Posted Jan 7, 2010
Authored by His0k4, Simo36

Novell eDirectory version 8.8 SP5 post authorization remote buffer overflow exploit.

tags | exploit, remote, overflow
SHA-256 | e4717073408a321c6c8d5bcd8643d68090de5191d64938212bef8b1f5b834fd4
phpAV Code Auditing Tool 1.1
Posted Jan 7, 2010
Authored by Milos Zivanovic

phpAV is a script designed to work as antivirus for malicious PHP scripts. It will search a given directory and related files for dangerous functions and provide a report.

tags | web, php
SHA-256 | 68ab3725b4466890a2330c5c5dd11622666a09c408af5bb5c60f44d048036ba0
Page 2 of 3
Back123Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close