what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 362 RSS Feed

Files Date: 2014-01-01 to 2014-01-31

GoToMeeting Information Disclosure
Posted Jan 26, 2014
Authored by Claudio J. Lacayo

GoToMeeting Android application (com.citrixonline.android.gotomeeting-1.apk) version 5.0.799.1238 is vulnerable to information disclosure via logging output, resulting in the leak of userID, meeting details, and authentication tokens. Android applications with permissions to read system log files may obtain the leaked information.

tags | exploit, info disclosure
advisories | CVE-2014-1664
SHA-256 | 389df097f281daaa7d9dbb9c56c808dd4446da2ce103d5ebb8de28f30a998b7d
WordPress SS Downloads Cross Site Scripting
Posted Jan 26, 2014
Authored by ACC3SS

WordPress SS Downloads plugin suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | e7e32f80a9b115f22a4c04630e2287e8ec3e6d477abe62b6eeeca82b4b163304
Simple e-Document 1.31 SQL Injection / XSS / CSRF / File Upload
Posted Jan 26, 2014
Authored by PuN!Sh3r

Simple e-Document version 1.31 suffers from login bypass, cross site request forgery, cross site scripting, remote shell upload, remote SQL injection, and various other vulnerabilities.

tags | exploit, remote, shell, vulnerability, xss, sql injection, csrf
SHA-256 | d8e915c9f3da5e00522f2f5a23346a479926590b24a8d0c3da5e67600297bd00
WordPress Seo Link Rotator Cross Site Scripting
Posted Jan 26, 2014
Authored by ACC3SS

WordPress Seo Link Rotator plugin suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 396ce83d6ac42563fd0a710f4db39ced9b30c7118dc539f7f1e5c4936c37f350
Apache Cordova / PhoneGap Whitelist Bypass
Posted Jan 26, 2014

The whitelisting functionality in Apache Cordova/PhoneGap suffers from multiple vulnerabilities.

tags | advisory, vulnerability, bypass
SHA-256 | bf6c217f2c3f51ae1155eb33fcaa924979dee83db65e026dcd837d354f6d4dfb
SkyBlueCanvas CMS 1.1 r248-03 Command Injection
Posted Jan 25, 2014
Authored by Scott Parish

SkyBlueCanvas CMS version 1.1 r248-03 suffers from a remote command injection vulnerability.

tags | exploit, remote
SHA-256 | edb1dc8edd44d6d33407ec7f1003b2866b604f61799c9db86b8103a2b24694b3
Drupal 7.14 EventCalendar Cross Site Scripting
Posted Jan 25, 2014
Authored by help AG Middle East

Drupal version 7.14 EventCalendar suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2014-1607
SHA-256 | 1f3e58de44388bcc99c04ff88aaf23d52abd1dac99f452c857af5d0c9f80660e
SSH Back 1.0
Posted Jan 25, 2014
Authored by Jobe

SSH Back is a set of shell scripts that assist you in shuffling an ssh connection over socat and ssl.

tags | tool, shell
systems | unix
SHA-256 | 09af0387a939825a564d95498365c96e775d71722a4345510eaa553305ecb667
Mp3info Stack Buffer Overflow
Posted Jan 25, 2014
Authored by Juan Sacco

Mp3info local buffer overflow denial of service exploit that spikes CPU usage.

tags | exploit, denial of service, overflow, local
SHA-256 | b5deb6a792d6a949d3e5e679490e6aa9c87258ed31e39e318f17e5babbae1e81
DAVOSET 1.1.6
Posted Jan 25, 2014
Authored by MustLive

DAVOSET is a tool for committing distributed denial of service attacks using execution on other sites.

Changes: Various updates and added support.
tags | tool, denial of service
SHA-256 | 414e38c5d3ecc466d6afb732c1e3b474933f86631afb8d31464bcd5b0317d142
pChart 2.1.3 Cross Site Scripting / Directory Traversal
Posted Jan 24, 2014
Authored by Balazs Makany

pChart version 2.1.3 suffers from cross site scripting and directory traversal vulnerabilities.

tags | exploit, vulnerability, xss, file inclusion
SHA-256 | b4febd30f5ce93221ca07adaa67509442b41b186e1b14b8debfe2154c84000b8
Debian Security Advisory 2826-2
Posted Jan 24, 2014
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2826-2 - A regression has been found on the denyhosts packages fixing CVE-2013-6890. This regression could cause an attempted breakin attempt to be missed by denyhosts, which would then fail to enforce a ban.

tags | advisory
systems | linux, debian
advisories | CVE-2013-6890
SHA-256 | 1bbcb2ef9cd6819e795dc162ddb5c7da744ee0f48217762ade9f578929c5dbef
Mandriva Linux Security Advisory 2014-024
Posted Jan 24, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-024 - Multiple buffer overflow vulnerabilities in graphviz due to an error within the yyerror() function (lib/cgraph/scan.l) which can be exploited to cause a stack-based buffer overflow via a specially crafted file.and the acceptance of an arbitrarily long digit list by a regular expression matched against user input. A build problem was discovered and fixed in swig while building graphviz for Business Server 1, related to the new php-5.5.x version as of the MDVSA-2014:014 advisory. Fixed swig packages is being provided with this advisory as well.

tags | advisory, overflow, php, vulnerability
systems | linux, mandriva
advisories | CVE-2014-0978, CVE-2014-1236
SHA-256 | 6996dd421efa9117f4b483fc6c479c51d2d2854a243ed739ddb0e740fc9be9d1
Mandriva Linux Security Advisory 2014-023
Posted Jan 24, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-023 - It was discovered that the HPLIP Polkit daemon incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files. It was discovered that HPLIP contained an upgrade tool that would download code in an unsafe fashion. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to execute arbitrary code.

tags | advisory, remote, arbitrary, local
systems | linux, mandriva
advisories | CVE-2013-6402, CVE-2013-6427
SHA-256 | 91e13eb8f7923827c581c119376fd7f9a940365f7e3775d6636dfeb8210cd760
Mandriva Linux Security Advisory 2014-022
Posted Jan 24, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-022 - Multiple flaws were found in the way Augeas handled configuration files when updating them. An application using Augeas to update configuration files in a directory that is writable to by a different user (for example, an application running as root that is updating files in a directory owned by a non-root service user) could have been tricked into overwriting arbitrary files or leaking information via a symbolic link or mount point attack. A flaw was found in the way Augeas handled certain umask settings when creating new configuration files. This flaw could result in configuration files being created as world writable, allowing unprivileged local users to modify their content.

tags | advisory, arbitrary, local, root
systems | linux, mandriva
advisories | CVE-2012-0786, CVE-2012-0787, CVE-2013-6412
SHA-256 | a4e7b7f5fa921c10736f914500d3700c44b196142c7c1c7ad4fde57f33181a71
Mandriva Linux Security Advisory 2014-021
Posted Jan 24, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-021 - It was reported that perl-Proc-Daemon, when instructed to write a pid file, does that with a umask set to 0, so the pid file ends up with mode 666, allowing any user on the system to overwrite it.

tags | advisory, perl
systems | linux, mandriva
advisories | CVE-2013-7135
SHA-256 | 05feabcd42048ef05480549d29b92bb9644404398225353fca335e295da4c1c2
JAMon 2.7 Cross Site Scripting
Posted Jan 24, 2014
Authored by Christian Catalano

JAMon version 2.7 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
advisories | CVE-2013-6235
SHA-256 | 05d3cecf7d59ce888a09043a4aa1af1988abd9d302ed9dd5da80c76ff2e50e0a
Ubuntu Security Notice USN-2089-1
Posted Jan 24, 2014
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 2089-1 - Several vulnerabilities were discovered in the OpenJDK JRE related to information disclosure and data integrity. An attacker could exploit these to expose sensitive data over the network. Several vulnerabilities were discovered in the OpenJDK JRE related to availability. An attacker could exploit these to cause a denial of service. Various other issues were also addressed.

tags | advisory, denial of service, vulnerability, info disclosure
systems | linux, ubuntu
advisories | CVE-2013-5804, CVE-2014-0411, CVE-2013-5910, CVE-2013-5820, CVE-2014-0376, CVE-2014-0416, CVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884, CVE-2014-0368, CVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850, CVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408, CVE-2014-0422, CVE-2014-0428, CVE-2014-0423, CVE-2013-3829, CVE-2013-4002, CVE-2013-5772
SHA-256 | df92bc480d2bbe6892b45b34f1f7ef44d0eca78db48442c04a95810382a58c45
Ubuntu Security Notice USN-2088-1
Posted Jan 24, 2014
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 2088-1 - Brian Smith discovered that NSS incorrectly handled the TLS False Start feature. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to spoof SSL servers.

tags | advisory, remote, spoof
systems | linux, ubuntu
advisories | CVE-2013-1740
SHA-256 | a0185fb2945b52f58676814f7c2d5a0d59a2bdc2468d9bf7fdbf55f2e85626b7
Ubuntu Security Notice USN-2087-1
Posted Jan 24, 2014
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 2087-1 - It was discovered that NSPR incorrectly handled certain malformed X.509 certificates. A remote attacker could use a crafted X.509 certificate to cause NSPR to crash, leading to a denial of service, or possibly execute arbitrary code.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2013-5607
SHA-256 | 68b326ff5a9d1bc5579dcfa9d4d047a99dd6f38fdc19188032d750ad6a1721de
Debian Security Advisory 2848-1
Posted Jan 24, 2014
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2848-1 - Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.35. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2013-5891, CVE-2013-5908, CVE-2014-0386, CVE-2014-0393, CVE-2014-0401, CVE-2014-0402, CVE-2014-0412, CVE-2014-0420, CVE-2014-0437
SHA-256 | 8de1a42f32bbbd17b73175f40ccc257f1623775f9476c9721e9cee2e5ee35c38
Gentoo Linux Security Advisory 201401-26
Posted Jan 24, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201401-26 - A vulnerability in Zabbix could allow remote attackers to execute arbitrary shell code. Versions less than 2.2.0-r4 are affected.

tags | advisory, remote, arbitrary, shell
systems | linux, gentoo
advisories | CVE-2013-6824
SHA-256 | e0fb59bd4a266a7be27464719a779471253f871e5060cc531de6395af2005985
Adult Webmaster PHP Password Disclosure
Posted Jan 24, 2014
Authored by vinicius777

Adult Webmaster PHP suffers from a remote password disclosure vulnerability.

tags | exploit, remote, php, info disclosure
SHA-256 | 5d256374da1c00ac65c89f84b2c767a7ce7a1f53d34c06fd56dd71fcdf7c38b1
Apple Security Advisory 2014-01-22-1
Posted Jan 24, 2014
Authored by Apple | Site apple.com

Apple Security Advisory 2014-01-22-1 - iTunes 11.1.4 is now available and addresses multiple security issues related to content control, code execution, and more. libxml and libxslt have also been updated to address memory corruption and code execution issues.

tags | advisory, code execution
systems | apple
advisories | CVE-2011-3102, CVE-2012-0841, CVE-2012-2807, CVE-2012-2825, CVE-2012-2870, CVE-2012-2871, CVE-2012-5134, CVE-2013-1024, CVE-2013-1037, CVE-2013-1038, CVE-2013-1039, CVE-2013-1040, CVE-2013-1041, CVE-2013-1042, CVE-2013-1043, CVE-2013-1044, CVE-2013-1045, CVE-2013-1046, CVE-2013-1047, CVE-2013-2842, CVE-2013-5125, CVE-2013-5126, CVE-2013-5127, CVE-2013-5128, CVE-2014-1242
SHA-256 | 88e0818e053952a3bd2eb65f69993d1a072ba9bb5eaaa9ed5388a10cd7518e9e
XOS Shop 1.0RC7o SQL Injection
Posted Jan 24, 2014
Authored by JoKeR_StEx

XOS Shop version 1.0RC7o suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 1e0e8100901e6b54d82414baef8ff4d635720aa18959798a0e446a285227c175
Page 3 of 15
Back12345Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close