what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 32 RSS Feed

Files Date: 2012-06-04 to 2012-06-05

PyroCMS 2.1.1 CRLF Injection / Stored Cross Site Scripting
Posted Jun 4, 2012
Authored by LiquidWorm | Site zeroscience.mk

PyroCMS version 2.1.1 suffers from CRLF injection and stored cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 5053cd5681c7e2370439dde2d747575873c3c5195878aafc31db53687d0ef75e
Mod_auth_pubtkt 0.7
Posted Jun 4, 2012
Site neon1.net

mod_auth_pubtkt is a simple Web single sign-on (SSO) solution for Apache. It validates authentication tickets provided by the client in a cookie using public-key cryptography (DSA or RSA). Thus, only the login server that generates the tickets needs to possess the private key, while Web servers can verify tickets given only the public key. The implementation of the login server is left to the user, but an example and a library in PHP are provided with the distribution.

Changes: The public key can be set per directory instead of only globally. The login URL is now optional, and a new TKTAuthBadIPURL option has been added. Furthermore, the module now compiles with Apache 2.4 and includes a Perl ticket generation module.
tags | web, php
systems | unix
SHA-256 | 8ff3de9c5acc026c6fd74fd8e599c0c2659cd29c51693dbf67a8bf8c609be94e
ISC BIND 9.x Denial Of Service
Posted Jun 4, 2012
Site isc.org

ISC Security Advisory - The handling of zero length rdata can cause named to terminate unexpectedly.

tags | advisory, denial of service
advisories | CVE-2012-1667
SHA-256 | fc123558f95ccb6b2d994cac429265085c0cb3db3caf42feccbfa83715e336c5
EUSecWest 2012 Call For Papers
Posted Jun 4, 2012
Site eusecwest.com

The seventh annual EUSecWest applied technical security conference - where the eminent figures in the international security industry get together share best practices and technology - will be held in downtown Amsterdam near Leidseplein Square on September 19/20, 2012. The most significant new discoveries about computer network hack attacks and defenses, commercial security solutions, and pragmatic real world security experience will be presented in a series of informative tutorials. This is the Call For Papers.

tags | paper, conference
SHA-256 | 73ac8a41554f9ccb3147b8d66807d54eb71c1fb95d025fa3bfdc12562e584f7b
Zoph 0.9pre2 CSRF / File Disclosure / SQL Injection
Posted Jun 4, 2012
Authored by KedAns-Dz

Zoph version 0.9pre2 suffers from cross site request forgery, remote file disclosure, and remote blind SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection, info disclosure, csrf
SHA-256 | 865a2df0f072694ea17b80a8230b7ca7e96ee5bb8f33c6a27d742f75a8af1e29
Mnews 1.1 SQL injection
Posted Jun 4, 2012
Authored by WhiteCollarGroup

Mnews versions 1.1 and below suffer from a remote SQL injection vulnerability in view.php.

tags | exploit, remote, php, sql injection
SHA-256 | f37e996cf5f9e2018f48d8178c7806bc499bea1a350d778f745b349dbd6e126e
Della CMS SQL Injection
Posted Jun 4, 2012
Authored by Mr.XpR

Della CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | c37c58d1b6ea4049a82103f8f17cbb15a2b8207cd0af6227c25d7be8e567e625
Sysax 5.60 Create SSL Certificate Buffer Overflow
Posted Jun 4, 2012
Authored by Craig Freyman

Sysax versions 5.60 and below suffer from a buffer overflow vulnerability when creating an SSL certificate.

tags | exploit, overflow
SHA-256 | 25b09a6e92ff4d9c00a80eaae87713ec5fe32db0a7d9c1c488dd9ed1a7a31810
Xtemplate Shell Upload
Posted Jun 4, 2012
Authored by Th3-Skywalk3r

Xtemplate suffers from a shell upload vulnerability.

tags | exploit, shell
SHA-256 | 3fb8a8f1839994c0a90059508ac4a5a8651537183bcc1591a30a6b85dbe58f98
Hexamail Server 4.4.5 Cross Site Scripting
Posted Jun 4, 2012
Authored by modpr0be

Hexamail Server versions 4.4.5 and below suffer from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 160e361b2554abab89535e34bcabe535be38225dbc0d072c307a624af2a5e429
Dblog 1.4.1 Insecure Session / Access Bypass
Posted Jun 4, 2012
Authored by L3b-r1'z

Dblog version 1.4.1 suffers from an access bypass vulnerability.

tags | exploit, bypass
SHA-256 | b385b6d7bfd3e487033ccfb40153e6b9b3e9d4761dab6f1dcb1a584ab7a75cd9
Msi.com Cross Site Scripting
Posted Jun 4, 2012
Authored by Ryuzaki Lawlet

Msi.com suffers from a cross site scripting vulnerability. The site has not responded to the author's reports regarding the vulnerability.

tags | exploit, xss
SHA-256 | c9d97b74fc7322f89c01f534cb33e2c2db7bb0dece41a50b13206dcb3db28bb4
Webex Eshop Builder SQL Injection
Posted Jun 4, 2012
Authored by Mr.XpR

Webex Eshop Builder suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 53807b7190bca361ba569db5d63095ff3c4050f49921ae4d601370de5b411cd3
IM Storm SQL Injection
Posted Jun 4, 2012
Authored by AtlasTeam

IM Storm suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 23ae844bc361dab22b50b11509895854cf69f2c1305e87c923363e640adb863d
Indexu 7 PHP Code Injection
Posted Jun 4, 2012
Authored by L3b-r1'z

Indexu 7 suffers from a remote PHP code injection vulnerability.

tags | exploit, remote, php
SHA-256 | 816257c2816d75a46511ee3959c91e8516dcbe49e98c8a1eb5afca48485cdc5e
CMS Faethon 1.3.4 SQL Injection
Posted Jun 4, 2012
Authored by AtlasTeam

CMS Faethon version 1.3.4 suffers from a remote SQL injection vulnerability. This is against a very old version of this software.

tags | exploit, remote, sql injection
SHA-256 | 459859a75f9b4c84edc8f4f38a5293b2f0696b2ca5646089b7ca33c4948f94d7
Secunia Security Advisory 49379
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Henry Hoggard has discovered two vulnerabilities in the Poll plugin for Vanilla Forums, which can be exploited by malicious users to conduct script insertion attacks.

tags | advisory, vulnerability
SHA-256 | 955f4a598b0dbb324741b15774fab7683a28ab752b4a66bd131f2dd0c90346af
Secunia Security Advisory 49383
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Gentoo has issued an update for qt-gui. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise an application using the library.

tags | advisory, denial of service
systems | linux, gentoo
SHA-256 | 76648c6a7cbc4c092edb6928fbf1ff8e6989e39ed29c170b00b6004a32df4e7e
Secunia Security Advisory 49334
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Multiple vulnerabilities have been reported in Bloxx Web Filtering, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to bypass certain security restrictions and conduct cross-site scripting, cross-site request forgery, and script insertion attacks.

tags | advisory, web, vulnerability, xss, csrf
SHA-256 | 71f3c4b73a247ce9f9147f0dfcb375b83ce587373e1c731d0aef058092c3886d
Secunia Security Advisory 49364
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Debian has issued an update for nut. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.

tags | advisory
systems | linux, debian
SHA-256 | f9e1c8e982c1bd494df2101c01f85f0ec1df2615ed9aba2c067e2a211359d1ef
Secunia Security Advisory 49338
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in ISC BIND, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial of Service).

tags | advisory, denial of service
SHA-256 | fd0981b313ebf39d1d6dabbd2b5b927d698fed95ff2cf89e78890b935e02fa32
Secunia Security Advisory 49312
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Symfony, which can be exploited by malicious people to conduct session fixation attacks.

tags | advisory
SHA-256 | f81aed8917c112893b0fc804be9d7681a501ba4ec0beba822713cc07a914eeb0
Secunia Security Advisory 49374
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - SUSE has issued an update for the kernel. This fixes two vulnerabilities, which can be exploited by malicious, local users to potentially gain escalated privileges and by malicious people to cause a DoS (Denial of Service).

tags | advisory, denial of service, kernel, local, vulnerability
systems | linux, suse
SHA-256 | 1a6a31dd8a71880ccec32738a88421ec9bb125591a8c40528def7a277e83e3b1
Secunia Security Advisory 49380
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Henry Hoggard has discovered a vulnerability in Vanilla Forums, which can be exploited by malicious users to conduct script insertion attacks.

tags | advisory
SHA-256 | eba0ee21289bcc19a09c7135ca23bbe3ea711278f97cd281d04191752d0bd9df
Secunia Security Advisory 49330
Posted Jun 4, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Multiple vulnerabilities have been reported in Piwik, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks, disclose potentially sensitive information, and cause a DoS (Denial of Service).

tags | advisory, denial of service, vulnerability, xss, csrf
SHA-256 | d72bb78b0941fdab165353f10c776f31e743b2212bd6ada1eca2cc6eb218ccb4
Page 1 of 2
Back12Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close