what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 427 RSS Feed

Files Date: 2014-02-01 to 2014-02-28

VideoWhisper Live Streaming Integration 4.27.3 XSS / Shell Upload / Traversal
Posted Feb 27, 2014
Authored by High-Tech Bridge SA | Site htbridge.com

VideoWhisper Live Streaming Integration version 4.27.3 suffers from cross site scripting, remote shell upload, information exposure, and path traversal vulnerabilities.

tags | exploit, remote, shell, vulnerability, xss, file inclusion
advisories | CVE-2014-1905, CVE-2014-1906, CVE-2014-1907, CVE-2014-1908
SHA-256 | 8589343b28cf5465cb971032b90d3806ffa103808d0ea8ff3382c08d32bb6003
GoldMP4Player 3.3 Buffer Overflow
Posted Feb 27, 2014
Authored by metacom

GoldMP4Player version 3.3 local buffer overflow exploit.

tags | exploit, overflow, local
SHA-256 | e5381967f3870c2e06479eae5f6fe202bb149136fc53d671df52b80010800799
German Telekom Local File Inclusion
Posted Feb 27, 2014
Authored by Ibrahim El-Sayed, Vulnerability Laboratory | Site vulnerability-lab.com

The German Telekom website suffered from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | b7fa37b22bc4bbcb19ac1e882d221051ad4c3c393229e09724ecba5cb14413d5
Bluetooth Photo Share Pro 2.0 Local File Inclusion / File Upload
Posted Feb 27, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Bluetooth Photo Share Pro version 2.0 suffers from local file inclusion and remote arbitrary file upload vulnerabilities.

tags | exploit, remote, arbitrary, local, vulnerability, file inclusion, file upload
SHA-256 | 373723247bb674fdb182129aadcb6edbb943fb7ba1f53545391908392eb3d231
SAS 9.2 / 9.3 / 9.4 Local Buffer Overflow
Posted Feb 27, 2014
Authored by Rene Freingruber | Site sec-consult.com

SAS for Windows versions 9.2, 9.3, and 9.4 suffer from a local buffer overflow vulnerability.

tags | advisory, overflow, local
systems | windows
SHA-256 | 24769861835016b127bed896f8ade5c050efa0a1c159a8540888d617d43db899
GroupOffice 5.0.44 Cross Site Scripting
Posted Feb 27, 2014
Authored by HauntIT

GroupOffice version 5.0.44 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 5e9ecb41f455fc5ce8462aa3f2c84f75038ea0fb008529aa2033cd378c59c892
PHP-CMDB 0.7.3 Cross Site Scripting / SQL Injection
Posted Feb 27, 2014
Authored by HauntIT

PHP-CMDB version 0.7.3 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, php, vulnerability, xss, sql injection
SHA-256 | a67d8b34f99f51d05ba0d86b8dd9d16c2587342e99d7267c8f8f0d015c02ef63
X2Engine 3.7.3 Cross Site Scripting / Shell Upload / SQL Injection
Posted Feb 27, 2014
Authored by HauntIT

X2Engine version 3.7.3 suffers from cross site scripting, remote shell upload, and remote SQL injection vulnerabilities.

tags | exploit, remote, shell, vulnerability, xss, sql injection
SHA-256 | d3c14e2d6ce07bb3835b1588b086b2b1c63408940f717a399617a80e062e48bc
PHP Calendar 2.0.1 XSS / Information Disclosure
Posted Feb 27, 2014
Authored by HauntIT

PHP Calendar version 2.0.1 suffers from multiple cross site scripting and information disclosure vulnerabilities.

tags | exploit, php, vulnerability, xss, info disclosure
SHA-256 | d2a72263079a61bd29ed5e7830991d421fa3083c72d80bbfeee5123fb35db2d3
Moodle 2.6.1 Cross Site Scripting
Posted Feb 27, 2014
Authored by HauntIT

Moodle version 2.6.1 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | f982e66358058f04f37c7d3427ec64943263e1f5f996338826132ed3cb5e0ea1
Open-School Community Edition 2.2 Cross Site Scripting
Posted Feb 27, 2014
Authored by HauntIT

Open-School Community Edition version 2.2 suffers from multiple persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 8cfad8b0dbd6d1dc9edaaf32671ea326da8545af162c775f2ba22e84502b655e
Office 365 Account Hijacking
Posted Feb 27, 2014
Authored by Gery Oei

This is a write up that discusses the Office 365 account hijacking via a known cookie re-use flaw with additional information.

tags | exploit
SHA-256 | 8b145eea262a37634ef49cfb4f85780277f702f002b5acc7ddeedc40869e28d9
Barracuda Networks Backup Appliance Cross Site Scripting
Posted Feb 27, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Barracuda Networks Backup Appliance suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f4d19a941a32473be3476c14e4dd4d786e3314d84fc3533afcc5beffd9e90f0d
VideoWhisper Video Conference Cross Site Scripting
Posted Feb 27, 2014
Authored by HauntIT

VideoWhisper Video Conference CMS suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | ada59ed47e25c9aa182b43c0f1224c9573103add6abeb21639c8371f889c853e
Cisco Security Advisory 20140226-pi
Posted Feb 26, 2014
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - A vulnerability in Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands with root-level privileges. The vulnerability is due to improper validation of URL requests. An attacker could exploit this vulnerability by requesting an unauthorized command via a specific URL. Successful exploitation could allow an authenticated attacker to execute system commands with root-level privileges. Cisco has released free software updates that address this vulnerability. A software patch that addresses this vulnerability in all affected versions is also available. Workarounds that mitigate this vulnerability are not available.

tags | advisory, remote, arbitrary, root
systems | cisco
SHA-256 | 2085552f3da2a1de4ba3036cf8124df7234b01446b9bb08ae5f19907c7e9ae85
HP Security Bulletin HPSBST02955
Posted Feb 26, 2014
Authored by HP | Site hp.com

HP Security Bulletin HPSBST02955 - Potential security vulnerabilities have been identified in 3rd party software used in HP XP P9000 Performance Advisor running Oracle and Apache Tomcat Software. HP has updated the Apache Tomcat and Oracle database software to address vulnerabilities affecting confidentiality, availability, and integrity. Revision 1 of this advisory.

tags | advisory, vulnerability
advisories | CVE-2007-5333, CVE-2007-5342, CVE-2007-5461, CVE-2007-6286, CVE-2008-0002, CVE-2008-1232, CVE-2008-1947, CVE-2008-2370, CVE-2009-2693, CVE-2009-2901, CVE-2009-2902, CVE-2009-3548, CVE-2010-1157, CVE-2010-2227, CVE-2010-3718, CVE-2010-4172, CVE-2011-0013, CVE-2011-0534, CVE-2011-1184, CVE-2011-2204, CVE-2011-2481, CVE-2011-2526, CVE-2011-2729, CVE-2011-3190, CVE-2011-5035, CVE-2011-5062, CVE-2011-5063, CVE-2011-5064
SHA-256 | 7a0da1c21ab0ea1ff0e437cda710d643179e7469a520d96d54e7b1e4ad034845
Drupal Mime Mail 6.x / 7.x Access Bypass
Posted Feb 26, 2014
Authored by Heine Deelstra | Site drupal.org

Drupal Mime Mail third party module version 6.x and 7.x suffer from an access bypass vulnerability.

tags | advisory, bypass
SHA-256 | bcf2575491826b0710730dc39d915d6af8fe276f8edf30d29d0e119fe33af483
HP Security Bulletin HPSBPI02869 SSRT100936 3
Posted Feb 26, 2014
Authored by HP | Site hp.com

HP Security Bulletin HPSBPI02869 SSRT100936 3 - A potential security vulnerability has been identified with HP LaserJet MFP printers, HP Color LaserJet MFP printers, and certain HP LaserJet printers. The vulnerability could be exploited remotely to gain unauthorized access to files. Revision 3 of this advisory.

tags | advisory
advisories | CVE-2012-5221
SHA-256 | 4c59ce6eebc678501a609d6ecc4489c93d0aac9371b86e05604dad9152f1ca81
Drupal Content Locking 6.x / 7.x CSRF
Posted Feb 26, 2014
Authored by Eugen Mayer | Site drupal.org

Drupal Content Locking third party module versions 6.x and 7.x suffer from a cross site request forgery vulnerability.

tags | advisory, csrf
SHA-256 | 16cd79d67b6d805f59cc01b989a8be123d70328cbc9af0cc97a00012b4b6168d
Apple Security Advisory 2014-02-25-3
Posted Feb 26, 2014
Authored by Apple | Site apple.com

Apple Security Advisory 2014-02-25-3 - QuickTime 7.7.5 is now available and addresses multiple security issues related to denial of service and arbitrary code execution.

tags | advisory, denial of service, arbitrary, code execution
systems | apple
advisories | CVE-2013-1032, CVE-2014-1243, CVE-2014-1244, CVE-2014-1245, CVE-2014-1246, CVE-2014-1247, CVE-2014-1248, CVE-2014-1249, CVE-2014-1250, CVE-2014-1251
SHA-256 | d19d51684f4d799bc85e0de254dedd61e3c5f79f8604e717e35213ae98ea6da9
Apple Security Advisory 2014-02-25-2
Posted Feb 26, 2014
Authored by Apple | Site apple.com

Apple Security Advisory 2014-02-25-2 - Safari 6.1.2 and Safari 7.0.2 is now available and addresses an issue where visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

tags | advisory, arbitrary, code execution
systems | apple
advisories | CVE-2013-6635, CVE-2014-1268, CVE-2014-1269, CVE-2014-1270
SHA-256 | 5f115e3656944c57ae6ad7a470d49b01ef3a6dc1308fcc4e1edf5fa848043874
Apple Security Advisory 2014-02-25-1
Posted Feb 26, 2014
Authored by Apple | Site apple.com

Apple Security Advisory 2014-02-25-1 - OS X Mavericks 10.9.2 and Security Update 2014-001 is now available and addresses multiple security issues including the recent SSL vulnerability.

tags | advisory
systems | apple, osx
advisories | CVE-2011-3389, CVE-2013-1862, CVE-2013-1896, CVE-2013-4073, CVE-2013-4113, CVE-2013-4248, CVE-2013-5139, CVE-2013-5178, CVE-2013-5179, CVE-2013-5986, CVE-2013-5987, CVE-2013-6420, CVE-2013-6629, CVE-2014-1245, CVE-2014-1246, CVE-2014-1247, CVE-2014-1248, CVE-2014-1249, CVE-2014-1250, CVE-2014-1252, CVE-2014-1254, CVE-2014-1255, CVE-2014-1256, CVE-2014-1257, CVE-2014-1258, CVE-2014-1259, CVE-2014-1260, CVE-2014-1261
SHA-256 | 1d8f727073c1ea1d6289c8c7fa93c5237ad978b58d6ca700d78a6f12ea0f3b83
Barracuda Web Firewall 6.1.0.016 Cross Site Scripting
Posted Feb 26, 2014
Authored by Ateeq ur Rehman Khan, Vulnerability Laboratory | Site vulnerability-lab.com

Barracuda Web Firewall version 6.1.0.016 suffers from a persistent script insertion vulnerability.

tags | exploit, web
SHA-256 | fa8731752b65dbe18c0a5dcb5bf6a32f993c8ace5f0907cd6d1366c6fc2cce5d
HP Security Bulletin HPSBMU02966
Posted Feb 26, 2014
Authored by HP | Site hp.com

HP Security Bulletin HPSBMU02966 - A potential security vulnerability has been identified with HP Operations Orchestration. The vulnerability could be exploited to gain unauthorized access to information. Revision 1 of this advisory.

tags | advisory
advisories | CVE-2013-2071
SHA-256 | 32d365b078cb65bcb4beceeac0ade27c68c83a77127c990b36aeb5f30104c0ba
Ubuntu Security Notice USN-2122-1
Posted Feb 26, 2014
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 2122-1 - It was discovered that FreeRADIUS incorrectly handled unix authentication. A remote user could successfully authenticate with an expired password. Pierre Carrier discovered that FreeRADIUS incorrectly handled rlm_pap hash processing. An authenticated user could use this issue to cause FreeRADIUS to crash, resulting in a denial of service, or possibly execute arbitrary code. The default compiler options for affected releases should reduce the vulnerability to a denial of service. Various other issues were also addressed.

tags | advisory, remote, denial of service, arbitrary
systems | linux, unix, ubuntu
advisories | CVE-2011-4966, CVE-2014-2015, CVE-2011-4966, CVE-2014-2015
SHA-256 | 0a995469005a5d9cd6cf4dd533400746453f53f7672a93339e2f298e285126ef
Page 1 of 18
Back12345Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close