what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 101 - 125 of 393 RSS Feed

Files Date: 2019-03-01 to 2019-03-31

Jettweb PHP Hazir Haber Sitesi Scripti 3 SQL Injection
Posted Mar 25, 2019
Authored by Ahmet Umit Bayram

Jettweb PHP Hazir Haber Sitesi Scripti version 3 suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, php, vulnerability, sql injection
SHA-256 | 1dfdeff119f98894c17accc58259ed5c0d8c02c12603a27539fe482966363424
Jettweb PHP Hazir Haber Sitesi Scripti 2 SQL Injection
Posted Mar 25, 2019
Authored by Ahmet Umit Bayram

Jettweb PHP Hazir Haber Sitesi Scripti version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, php, sql injection
SHA-256 | d4ae00cf975e0bb60af51931f734a9a39e31fd1da9db18fefe3d40526da060da
WordPress Plugins Open Redirection 2019/03/25
Posted Mar 25, 2019
Authored by KingSkrupellos

Five WordPress plugins suffer from open redirection vulnerabilities. Affected includes The-CL-Amazon-Thingy plugin version 1.0, Google Document Embedder version 2.5.8, VJ-Slider version 1.0, WPUSW plugin version 1.0, and Angsumans Translator Gold version 2.3.

tags | exploit, vulnerability
SHA-256 | 36f1dd7eb09f0f5c42db2cb00886c36e29532e70f4ddb3ea55f9160ea164bca4
Jettweb PHP Hazir Haber Sitesi Scripti 1 SQL Injection
Posted Mar 24, 2019
Authored by Ahmet Umit Bayram

Jettweb PHP Hazir Haber Sitesi Scripti version 1 suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, php, vulnerability, sql injection
SHA-256 | 0b476151e6e7a9da395f1bf498774dc91d76b7d32aa71e0ce882aebfb3d57941
X-NetStat Pro 5.63 Local Buffer Overflow
Posted Mar 23, 2019
Authored by Peyman Forouzan

X-NetStat Pro version 5.63 local buffer overflow exploit with egghunter.

tags | exploit, overflow, local
SHA-256 | ad29a33d7abc1ae7479001879318ce054e61efe64749a92ca8d4f19dc5b2b11e
TCPDF 6.2.19 Deserialization / Remote Code Execution
Posted Mar 22, 2019
Authored by polict | Site polict.net

TCPDF versions 6.2.19 and below suffer from a deserialization vulnerability that can allow for remote code execution.

tags | exploit, remote, code execution
advisories | CVE-2018-17057
SHA-256 | c4935b1bec468d4305cf1499300d42f521083fed9900cd9b61485ae84fe7a467
Apache CouchDB 2.3.1 Cross Site Request Forgery / Cross Site Scripting
Posted Mar 22, 2019
Authored by Ozer Goker

Apache CouchDB version 2.3.1 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, csrf
SHA-256 | a8151accf125aaa23c543cc976db64a284b1027c29596ce6a1104e9da5b5eb45
Ubuntu Security Notice USN-3916-1
Posted Mar 22, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3916-1 - It was discovered that libsolv incorrectly handled certain malformed input. If a user or automated system were tricked into opening a specially crafted file, applications that rely on libsolv could be made to crash, resulting in a denial of service.

tags | advisory, denial of service
systems | linux, ubuntu
advisories | CVE-2018-20532
SHA-256 | 0a1588a1f320a52d90d846989ceddcdeac42599d44e9bb75a5cc345039d63c07
DNS Spider Multithreaded Bruteforcer 1.1
Posted Mar 22, 2019
Authored by noptrix | Site nullsecurity.net

DNS Spider is a multi-threaded bruteforcer of subdomains that leverages a wordlist and/or character permutation.

Changes: Added wildcard check. Updated built-in wordlist (23k).
tags | tool, scanner
systems | unix
SHA-256 | c8907d8f1866bfeb2cbff803208d108296b8c3d8c180e8ee0f109b19fd5cc91c
Debian Security Advisory 4413-1
Posted Mar 22, 2019
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4413-1 - A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of this flaw for local root privilege escalation.

tags | advisory, overflow, local, root
systems | linux, debian
advisories | CVE-2019-9755
SHA-256 | 34ced0862ac4a17c86d87be51f3cc3d1b1cad9c5abd8c31acda65c4c20bc6a34
WordPress Themes Open Redirection 2019/03/22
Posted Mar 22, 2019
Authored by KingSkrupellos

Many WordPress themes and a plugin suffer from open redirection vulnerabilities. Age-Verification plugins version 0.5 is affected. Themes affected include Ev version 1.x, Nine-Day version 1.6, Aibbt version 1.0, itiis version 1.x, ifxPro.Cn version 5.0, 2kqq version 5.2, Azzxx version 1.2.1, BigChrome version 5.2, clsn-003 version 1.0, Concise version 2.8, TaozHuji version 5.2, UsaMusic-PC version 1.0, Wngzs version 1.0, 2018110612035976 version 1.7.3, Begin4.6 version 4.6, Begin5.2 version 5.2, Begin44 version 4.4, BeginLTS version 6, Zangai version 1.1.0, Deep version 5.4, and Wopus version 1.0.

tags | exploit, vulnerability
SHA-256 | dde24f2673dd10b7c2098a95653b2d7e373925d002e9b0ef39cff99af5b5192b
Matri4Web Matrimony Web Script SQL Injection
Posted Mar 22, 2019
Authored by Ahmet Umit Bayram

Matri4Web Matrimony Web Script suffers from multiple remote SQL injection vulnerabilities.

tags | exploit, remote, web, vulnerability, sql injection
SHA-256 | 9722a5414dcae7db768184cd3c8f5974f012497e660a89988f627f4a5a397a4c
Inout Article Base CMS SQL Injection
Posted Mar 22, 2019
Authored by Ahmet Umit Bayram

Inout Article Base CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | d9d86983d8b5883be30094b7a11999dccaf24fbd920d47731c7fd8ef3a153401
I2P 0.9.39
Posted Mar 22, 2019
Authored by welterde | Site i2p2.de

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

Changes: Performance improvements. Various other updates.
tags | tool
systems | unix
SHA-256 | 105773e11481cfcea0bc69b932895890ba5dd5e8d59ec322f06743bf2f15d211
Ubuntu Security Notice USN-3917-1
Posted Mar 22, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3917-1 - The snapd default seccomp filter for strict mode snaps blocks the use of the ioctl system call when used with TIOCSTI as the second argument to the system call. Jann Horn discovered that this restriction could be circumvented on 64 bit architectures. A malicious snap could exploit this to bypass intended access restrictions to insert characters into the terminal's input queue. On Ubuntu, snapd typically will have already automatically refreshed itself to snapd 2.37.4 which is unaffected.

tags | advisory
systems | linux, ubuntu
advisories | CVE-2019-7303
SHA-256 | 13a2bdb1b443d25b262c5bc7b4b990dd9fd330319e9950c08bf7851a447bfb28
Ubuntu Security Notice USN-3918-1
Posted Mar 22, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3918-1 - Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, denial of service via successive FTP authorization prompts or modal alerts, trick the user with confusing permission request prompts, obtain sensitive information, conduct social engineering attacks, or execute arbitrary code. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2019-9788, CVE-2019-9791, CVE-2019-9792, CVE-2019-9793, CVE-2019-9797, CVE-2019-9799, CVE-2019-9802, CVE-2019-9803, CVE-2019-9805, CVE-2019-9808, CVE-2019-9809
SHA-256 | b4e53350aa233dd662095955993165e828a24f646ecc4eecc6a42c2dd5ddab2b
Ubuntu Security Notice USN-3913-1
Posted Mar 22, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3913-1 - It was discovered that p7zip did not correctly handle certain malformed archives. If a user or automated system were tricked into processing a specially crafted archive with p7zip, then p7zip could be made to crash, possibly leading to arbitrary code execution.

tags | advisory, code execution
systems | linux, ubuntu
advisories | CVE-2016-2335
SHA-256 | b03a7e886ada2e7ec0f39d5ec4879e5d2ea608024e30bdd12d3b64496be85d73
Ubuntu Security Notice USN-3915-1
Posted Mar 22, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3915-1 - It was discovered that Ghostscript incorrectly handled certain PostScript files. If a user or automated system were tricked into processing a specially crafted file, a remote attacker could possibly use this issue to access arbitrary files, execute arbitrary code, or cause a denial of service.

tags | advisory, remote, denial of service, arbitrary
systems | linux, ubuntu
advisories | CVE-2019-3835
SHA-256 | 785d89e6351285f26ba5954d1951f2c2bc5bd07172da38c843ae03bdfe77f796
Ubuntu Security Notice USN-3914-1
Posted Mar 22, 2019
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 3914-1 - A heap buffer overflow was discovered in NTFS-3G when executing it with a relative mount point path that is too long. A local attacker could potentially exploit this to execute arbitrary code as the administrator.

tags | advisory, overflow, arbitrary, local
systems | linux, ubuntu
advisories | CVE-2019-9755
SHA-256 | f9f198b31ea5cf57ccfde0dda69e04199f8228a0470296e15a62ce16bf4fe3b4
Red Hat Security Advisory 2019-0633-01
Posted Mar 22, 2019
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2019-0633-01 - The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed. Multiple vulnerabilities have been addressed.

tags | advisory, vulnerability
systems | linux, redhat
advisories | CVE-2019-3835, CVE-2019-3838
SHA-256 | 81e91f878664edfe24b631bddbedf394ff019eacbc69110849c182fffd2a8ab5
Meeplace Business Review Script SQL Injection
Posted Mar 22, 2019
Authored by Ahmet Umit Bayram

Meeplace Business Review Script suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 83a7a301e2f857fa3c3d70271b471f8a49dde213b4b2c8db73beab7e8ce5d933
snap seccomp TIOCSTI Blacklist Circumvention
Posted Mar 22, 2019
Authored by Google Security Research

snap uses a seccomp filter with a blacklist for TIOCSTI can be circumvented.

tags | exploit
advisories | CVE-2019-7303
SHA-256 | dfe93c7e631a95ac963d06c283dbec8208a04af5c084bb298266d147901f846c
Netartmedia Vlog System SQL Injection
Posted Mar 21, 2019
Authored by Ahmet Umit Bayram

Netartmedia Vlog System suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 3065e78776928ce93681dc474c38a1f577df20a98423dfd6a466b971013fc67e
Lynis Auditing Tool 2.7.3
Posted Mar 21, 2019
Authored by Michael Boelen | Site cisofy.com

Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.

Changes: Added detection for Lynis being scheduled (e.g. cronjob). Improved logging and various other changes were added.
tags | tool, scanner
systems | unix
SHA-256 | d05ea35b7739ccb6dbd9f0bbe5556cf759d65e3e4526f50b1d453ef3a9aad42b
NSS Netscape Certificate Sequences CERT_DecodeCertPackage() Crash
Posted Mar 21, 2019
Authored by Tavis Ormandy, Google Security Research

NSS suffers from a NULL dereference issue when parsing Netscape Certificate Sequences in CERT_DecodeCertPackage().

tags | exploit
SHA-256 | d7adf827b738a3a567689a46c8203967c3089100a538ccf2c1e1cb2e8236ad6c
Page 5 of 16
Back34567Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close