exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 50 RSS Feed

Files Date: 2010-07-08 to 2010-07-09

Freeciv 2.2.1 Denial Of Service
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

Freeciv version 2.2.1 suffers from denial of service vulnerabilities. Exploit included.

tags | exploit, denial of service, vulnerability
SHA-256 | 9d9e673eee5c1ce184752800c40c16a06d773e5a251dffdd15ceaf0a2a965042
Ghost Recon Advanced Warfighter 1 / 2 Overflows
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

Ghost Recon Advanced Warfighter versions 1 and 2 suffer from integer and array indexing overflows.

tags | advisory, overflow
SHA-256 | d973bcc1e6529953596abb97784dab67f32422d00caf4533203eb9fcab4cab84
Joomla ArtForms 2.1b7.2 RC2 Cross Site Scripting / SQL Injection / Directory Traversal
Posted Jul 8, 2010
Authored by Salvatore Fresta

The Joomla ArtForms component version 2.1b7.2 RC2 suffers from cross site scripting, remote SQL injection and directory traversal vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection, file inclusion
SHA-256 | 22ab97531f9b706153567472a552f4a7a1f71c20f48b853907cc14101e773a99
Pligg CMS 1.0.4 Cross Site Scripting
Posted Jul 8, 2010
Authored by Andrei Rimsa Alvares

Pligg CMS version 1.0.4 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 1e9a1773034cf732b523d0a050fc930039f7fe3bca02438d8d1f560b41f3e8bf
Mandriva Linux Security Advisory 2010-130
Posted Jul 8, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-130 - Certain invalid GSS-API tokens can cause a GSS-API acceptor (server) to crash due to a null pointer dereference in the GSS-API library. The updated packages have been patched to correct this issue.

tags | advisory
systems | linux, mandriva
advisories | CVE-2010-1321
SHA-256 | 5a363510cc86fa88ee8aa14537b88ea5f742ae16d68959c2ce6346cb423c3ff1
Mandriva Linux Security Advisory 2010-129
Posted Jul 8, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-129 - The krshd and v4rcp applications in MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion. The ftpd and ksu programs in MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. Certain invalid GSS-API tokens can cause a GSS-API acceptor (server) to crash due to a null pointer dereference in the GSS-API library. The updated packages have been patched to correct these issues.

tags | advisory, local
systems | linux, aix, mandriva
advisories | CVE-2006-3083, CVE-2006-3084, CVE-2010-1321
SHA-256 | 1229d0c29790afa2ad1dd4aa3ac27bed53aaf20094ab9e3f74e7252954698b5d
Cisco Security Advisory 20100707-snmp
Posted Jul 8, 2010
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - Cisco Industrial Ethernet 3000 (IE 3000) Series switches running Cisco IOS Software releases 12.2(52)SE or 12.2(52)SE1, contain a vulnerability where well known SNMP community names are hard-coded for both read and write access. The hard-coded community names are "public" and "private." Cisco recommends that all administrators deploy the mitigation measures outlined in the Workarounds section or perform a Cisco IOS Software upgrade. Cisco has released free software updates that address this vulnerability.

tags | advisory
systems | cisco
advisories | CVE-2010-1574
SHA-256 | 084a545cab9484dcba8b4e243ad0a6511c14890d442a8b0ee95360b78739111e
EA Battlefield 2 / Battlefield 2142 Multiple Arbitrary File Upload
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

The Refractor 2 engine in Battlefield 2 versions 1.50 and below and Battlefield 2142 versions 1.50 and below suffers from multiple arbitrary file upload vulnerabilities. Exploit included.

tags | exploit, arbitrary, vulnerability, file upload
SHA-256 | c719436be31cc3d812b256a0566b6669d91a7366594c74a49b5940eb5ce70c97
Sijio Community Software Cross Site Scripting / SQL Injection
Posted Jul 8, 2010
Authored by Sid3 effects

Sijio Community Software suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 3ee8771359c68d7212cf3ffd593f8c08ba054d283886e2f0508d2103a7d32c62
Pith CMS 0.9.5.1 Local File Inclusion / Remote File Inclusion
Posted Jul 8, 2010
Authored by eidelweiss

Pith CMS version 0.9.5.1 suffers from local file inclusion and remote file inclusion vulnerabilities.

tags | exploit, remote, local, vulnerability, code execution, file inclusion
SHA-256 | 944f761de10c44c7f3d4242687d18efc85529fad04f075287e62dcdcf7ee445e
PBS Pro Race Condition
Posted Jul 8, 2010
Authored by Bartlomiej Balcerek

PBS Pro versions prior to 10.4 o+w race condition proof of concept exploit.

tags | exploit, proof of concept
SHA-256 | e5ef3ff55ecaffc75cef785be9136ba14ff0bdba919b16c5d79092a7dd9aa824
Joomla Agora 2.5.x Pantheon Local File Inclusion
Posted Jul 8, 2010
Authored by wishnusakti, inc0mp13te

The Joomla Agora component version 2.5.x Pantheon suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 01ba5957315cf61ac22adc2847d10f62e297b6131b1fa44d25d747e71530de2f
Ubuntu Security Notice 959-1
Posted Jul 8, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 959-1 - Denis Excoffier discovered that the PAM MOTD module in Ubuntu did not correctly handle path permissions when creating user file stamps. A local attacker could exploit this to gain root privileges.

tags | advisory, local, root
systems | linux, ubuntu
advisories | CVE-2010-0832
SHA-256 | ee80f6498671ddd1880de5fd9eef46ad026443c9acbf99faf79213e554bb0b74
DCP-Portal 7.0 Beta Cross Site Scripting
Posted Jul 8, 2010
Authored by Andrei Rimsa Alvares

DCP-Portal version 7.0 Beta suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 5f29d882be595d9768ed26abfbba408f87e79b18363a209d2a36f0ecf34f4367
Exponent CMS 0.97.0 Cross Site Scripting
Posted Jul 8, 2010
Authored by Andrei Rimsa Alvares

Exponent CMS version 0.97.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 8aa450c58f1fa570aae00c8156418bd6234276a19273404886efb1529db1b33e
GSM SIM Utility Direct Local Buffer Overflow
Posted Jul 8, 2010
Authored by chap0

GSM SIM Utility Direct RET local buffer overflow exploit. Affects version 5.15.

tags | exploit, overflow, local
SHA-256 | 15de76ced43372497ecbe7c41e888d3800c73d203ba85bdcf15a693b20d9e5a9
Hero DVD 3.0.8 Buffer Overflow
Posted Jul 8, 2010
Authored by chap0

Hero DVD version 3.0.8 remote buffer overflow exploit.

tags | exploit, remote, overflow
SHA-256 | b96ff541e105a651045d18859fd6f9197a4aa071b0a112c09f988427f6a709df
Citibank CitiDirect Online Banking Forced Use Of Vulnerable JRE
Posted Jul 8, 2010
Authored by Tomasz Tometzky Ostrowski

Citibank CitiDirect Online Banking software forces use of a vulnerable version of the Java Runtime Environment.

tags | advisory, java
SHA-256 | 8f04afa2c637e5b11d002f0ed54ab72e8d083fd6b496899eee91fea841cf853c
A Newbies Guide To The Underground Volume 2
Posted Jul 8, 2010
Authored by Ratdance, Aviator753, Killab, MLS577

Whitepaper called A Serious Newbie's Guide to the Underground v2. This is a continuation of ratdance's original Newbie's guide to the underground.

tags | paper
SHA-256 | 59bcdfa72ce194a61cb1c9f4dd3e108ef30765965712acfa60e17b5d35dd1d26
Go Null Yourself E-Zine Issue 01
Posted Jul 8, 2010
Authored by gny | Site gonullyourself.org

Go Null Yourself E-zine Issue 1 - Topics in this issue include RTLO Spoofing, Alternate Data Streams, Derandomizing Perl's RNG, Trojaning OpenSSH and more.

tags | trojan, perl, spoof, magazine
SHA-256 | da764bb263f3ff2f6073ba91670651cedf533d2c37e234ff11609dae96d20245
Qt 4.6.3 Denial Of Service
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

Qt versions 4.6.3 and below suffer from a remote denial of service vulnerability. Exploit included.

tags | exploit, remote, denial of service
SHA-256 | a98ad307a19189b74621d8afdcf89966c842795c15ee9ef0845f54e7ed9b8ae5
Simple Document Management System SQL Injection
Posted Jul 8, 2010
Authored by Sid3 effects

Simple Document Management System suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 88efa68c54a312c573492fcc24e9e0d04236ac16f5e0b750b8c02ebd0212eb7b
Joomla PaymentsPlus Blind SQL Injection
Posted Jul 8, 2010
Authored by Sid3 effects

The Joomla PaymentsPlus component suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 749208d402b089deb4c26f92d5aec10135bc3459acca84b3db501bafcc835522
Green Shop SQL Injection
Posted Jul 8, 2010
Authored by Ashiyane Digital Security Team

Green Shop suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 010cf2f6e59e0c8286863da323a89d1fb3a85282ad28083b5b525a50463d1791
Polymorphic Shellcode Generator For ARM Architecture
Posted Jul 8, 2010
Authored by Jonathan Salwan

This is a polymorphic shellcode generator for ARM architecture that produces execve("/bin/sh", ["/bin/sh"], NULL).

tags | shellcode
SHA-256 | de860077ea38ffa4a008b24122c4949fb3e19f8ebbc539c89d975eae3bc82105
Page 2 of 2
Back12Next

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close