what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 41 of 41 RSS Feed

Files Date: 2011-10-12 to 2011-10-13

Evading Antimalware Engines Via Assembly Ghostwriting
Posted Oct 12, 2011
Authored by antiordinary

Whitepaper called Evading Antimalware Engines via Assembly Ghostwriting.

tags | paper
SHA-256 | c69ca241db8929c1badf0a2febd49a571ceddd5755b5f32dd8ef44146ffadb5c
Joomla Sgicatalog SQL Injection
Posted Oct 12, 2011
Authored by BHG Security Center

The Joomla Sgicatalog component version 1.x suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 7e6fab15f2a268c1137938fb9309a5f170d0acc7762964dcde58038e767631da
TugZip 3.5 Zip File Parsing Buffer Overflow
Posted Oct 12, 2011
Authored by mr_me, Lincoln, TecR0c, Stefan Marin | Site metasploit.com

This Metasploit module exploits a stack-based buffer overflow vulnerability in the latest version 3.5 of TugZip archiving utility. In order to trigger the vulnerability, an attacker must convince someone to load a specially crafted zip file with TugZip by double click or file open. By doing so, an attacker can execute arbitrary code as the victim user.

tags | exploit, overflow, arbitrary
advisories | CVE-2008-4779, OSVDB-49371
SHA-256 | dfd1d434ab7742db844f4361a73baede359a856715df5794ad3d96c86362e269
WordPress WP-SpamFree SQL Injection
Posted Oct 12, 2011
Authored by cheki

The WordPress WP-SpamFree plugin version 3.2.1 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 872940395fb43562df8533fff00f33859bbff0de3b2f6bf1464c7f15e9cecc42
Red Hat Security Advisory 2011-1364-01
Posted Oct 12, 2011
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2011-1364-01 - The kdelibs packages provide libraries for the K Desktop Environment. An input sanitization flaw was found in the KSSL API. An attacker could supply a specially-crafted SSL certificate to an application using KSSL, such as the Konqueror web browser, causing misleading information to be presented to the user, possibly tricking them into accepting the certificate as valid.

tags | advisory, web
systems | linux, redhat
advisories | CVE-2011-3365
SHA-256 | 42d57e16e44097171470596df1e3290bdb422e02da5b6b0fb5d50caa9a857888
Bypassing Windows 7 Kernel ASLR
Posted Oct 12, 2011
Authored by Stefan Le Berre

Whitepaper called Bypassing Windows 7 Kernel ASLR. In this paper, the author explains every step to code an exploit with a useful kernel ASLR bypass. Successful exploitation is performed on Windows 7 SP0 / SP1.

tags | paper, kernel, bypass
systems | windows
SHA-256 | 5c3994059d8384faf17163e5cb49cd471cedb061f14e2c2b7ef3cdb5ce5724aa
Cudoma SQL Injection
Posted Oct 12, 2011
Authored by Andrea Bocchetti

Cudoma suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | e43b96a3f7c6d5efacbe109185cff4c7644460261e78c88c815c2a5b219d0b14
Ubuntu Security Notice USN-1227-1
Posted Oct 12, 2011
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1227-1 - Ryan Sweat discovered that the kernel incorrectly handled certain VLAN packets. On some systems, a remote attacker could send specially crafted traffic to crash the system, leading to a denial of service. Timo Warns discovered that the EFI GUID partition table was not correctly parsed. A physically local attacker that could insert mountable devices could exploit this to crash the system or possibly gain root privileges. Various other issues were also addressed.

tags | advisory, remote, denial of service, kernel, local, root
systems | linux, ubuntu
advisories | CVE-2011-1576, CVE-2011-1776, CVE-2011-1833, CVE-2011-2213, CVE-2011-2497, CVE-2011-2699, CVE-2011-2700, CVE-2011-2723, CVE-2011-2918, CVE-2011-2928, CVE-2011-3191
SHA-256 | 87d2aaa8ca6ba6b00c9ca09b32765eba40fef19b74fb5429c7386a7141501ba4
Joomla JCE 2.0.10 Shell Upload
Posted Oct 12, 2011
Authored by AmnPardaz Security Research Team | Site bugreport.ir

Joomla JCE component version 2.0.10 shell uploading exploits written in PHP and Perl.

tags | exploit, shell, perl, php
SHA-256 | d1b4ac29ebde769a56c277231425f66928d9b1ae143eb1a76b6b2460dab7671a
ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 Administrative Access
Posted Oct 12, 2011
Authored by Roberto Paleari

ZOHO ManageEngine ADSelfService Plus version 4.5 Build 4521 suffers from an authentication bypass vulnerability.

tags | exploit, add administrator, bypass
advisories | CVE-2011-3485
SHA-256 | f77c06fcc32f7f659b5cbeae7e9a84e98c2c34c9153d7d9897701d57dfb559d4
Filmis 0.2 Beta Cross Site Scripting / SQL Injection
Posted Oct 12, 2011
Authored by M.Jock3R

Filmis version 0.2 Beta suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 635cc0c5fedf63470616e91144d46f5e705d459606e1f8eeb7bcad7f9a9506eb
Filmis 0.2 Cross Site Request Forgery / Cross Site Scripting
Posted Oct 12, 2011
Authored by indoushka

Filmis version 0.2 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 8b210a5c19e2f2ecfeb38873657519516d2e8337db4f6e5866e719b7d761b20a
HP Security Bulletin HPSBMU02710 SSRT100601
Posted Oct 12, 2011
Authored by HP | Site hp.com

HP Security Bulletin HPSBMU02710 SSRT100601 - A potential security vulnerability has been identified with HP Onboard Administrator (OA). The vulnerability could be exploited remotely to gain unauthorized access. Revision 1 of this advisory.

tags | advisory
advisories | CVE-2011-3155
SHA-256 | 8224be93c871c8c41eb80eb778a040f90039abdc72505dc40639b6913e85eaa7
SilverStripe 2.4.5 Cross Site Scripting
Posted Oct 12, 2011
Authored by Stefan Schurtz

SilverStripe version 2.4.5 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | f4b756b891416720dcce945f3a627a076dbfa53794a000265f292275c636a60d
Contao 2.10 Cross Site Scripting
Posted Oct 12, 2011
Authored by Stefan Schurtz

Contao version 2.10 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | eba693da943cfa776b5b0ec54e3b955c461838891e36136ceb646cd40b62344d
ABUS TVIP 11550/21550 File Read / File Upload / Command Execution
Posted Oct 12, 2011
Authored by Marco van Berkum

ABUS TVIP 11550/21550 suffers from arbitrary file read, file upload, and command execution vulnerabilities.

tags | exploit, arbitrary, vulnerability, file upload
SHA-256 | 2f51d4760c8bd61052e7053ffd77dd4337c961386e2656f7ff4271440419c1b2
Page 2 of 2
Back12Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    0 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close