exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 100 RSS Feed

Files

WordPress Squirrel Theme 1.6.4 Remote File Inclusion
Posted Dec 8, 2015
Authored by indoushka

WordPress Squirrel Theme version 1.6.4 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 86c56b7e4874d7528b43160cb98e7dd014fc64e5f89c14c40edacd196b5285d4

Related Files

WordPress + Buddypress + Blogs Mu Theme Cross Site Scripting
Posted Sep 25, 2011
Authored by knull | Site leethack.info

WordPress with Buddypress and Blogs Mu Theme suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | cdc514f2e390d0fb253eaff6f745da7c608e34926bb03c0bcb321ab265c56eac
Freeamp 2.0.7 (FAT File) Stack Buffer Overflow
Posted Aug 4, 2011
Authored by James Fitts, Ivan Garcia Ferreira | Site metasploit.com

This Metasploit module exploits a buffer overflow vulnerability found in Freeamp 2.0.7. The overflow occurs when an overly long string is parsed in the FAT file. This Metasploit module creates a txt file that has to be used in the creation of a FAT file. The FAT file then has to be imported as a theme. To create the FAT file you need to first decompress the basic theme template, MakeTheme -d freeamp.fat. Next create the new FAT file MakeTheme crash.fat theme.xml title.txt *.bmp.

tags | exploit, overflow
SHA-256 | 6dfcaf1f8aff9ad6e428e3ae8e6f8b05df47336a37bbdba3dccbb68f5018292e
Secunia Security Advisory 45472
Posted Aug 4, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in the iWebkit theme for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

tags | advisory
SHA-256 | 1d9c28c643797a139fc13d2bf15f040c13abdb58d5f55745e68d1b7e926360e0
Secunia Security Advisory 45113
Posted Jul 7, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in the Facebook Simple Clean theme for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

tags | advisory
SHA-256 | 20189da09b4effcc1f1eb189193d3e724fa8da5afdf96273e9029f2878763e95
Ubuntu Security Notice USN-1157-2
Posted Jun 23, 2011
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1157-2 - USN-1157-1 fixed vulnerabilities in Firefox. This update provides updated packages for use with Firefox 5. Bob Clary, Kevin Brosnan, Gary Kwong, Jesse Ruderman, Christian Biesinger, Bas Schouten, Igor Bukanov, Bill McCloskey, Olli Pettay, Daniel Veditz and Marcia Knous discovered multiple memory vulnerabilities in the browser rendering engine. An attacker could possibly execute arbitrary code with the privileges of the user invoking Firefox. Martin Barbella discovered that under certain conditions, viewing a XUL document while JavaScript was disabled caused deleted memory to be accessed. An attacker could potentially use this to crash Firefox or execute arbitrary code with the privileges of the user invoking Firefox. Jordi Chancel discovered a vulnerability on multipart/x-mixed-replace images due to memory corruption. An attacker could potentially use this to crash Firefox or execute arbitrary code with the privileges of the user invoking Firefox. Chris Rohlf and Yan Ivnitskiy discovered an integer overflow vulnerability in JavaScript Arrays. An attacker could potentially use this to execute arbitrary code with the privileges of the user invoking Firefox. It was discovered that Firefox's WebGL textures did not honor same-origin policy. If a user were tricked into viewing a malicious site, an attacker could potentially view image data from a different site. Christoph Diehl discovered an out-of-bounds read vulnerability in WebGL code. An attacker could potentially read data that other processes had stored in the GPU. Christoph Diehl discovered an invalid write vulnerability in WebGL code. An attacker could potentially use this to execute arbitrary code with the privileges of the user invoking Firefox. It was discovered that an unauthorized site could trigger an installation dialog for addons and themes. If a user were tricked into viewing a malicious site, an attacker could possibly trick the user into installing a malicious addon or theme. Mario Heiderich discovered a vulnerability in displaying decoded HTML-encoded entities inside SVG elements. An attacker could utilize this to perform cross-site scripting attacks. Various other issues were also addressed.

tags | advisory, overflow, arbitrary, javascript, vulnerability, xss
systems | linux, ubuntu
SHA-256 | ab0de8b218db560872113e115b67dd7d3a8d9bab94d781b359d06958c84f7b71
Multiple WordPress Themes Cross Site Scripting
Posted Jun 6, 2011
Authored by MustLive

Multiple WordPress themes suffer from cross site scripting and information disclosure vulnerabilities. Themes affected include Live Wire (all three themes from Live Wire series), Gotham News, Typebased, Blogtheme, VibrantCMS, Fresh News, The Gazette Edition, NewsPress, The Station, The Original Premium News, Flash News, Busy Bee, and Geometric.

tags | exploit, vulnerability, xss, info disclosure
SHA-256 | 1a955659244778d9058139f1fa6493227ce6506d22be3379a1d102a1fa381170
Magazeen 1.0 Cross Site Scripting
Posted May 4, 2011
Authored by MustLive

Magazeen theme version 1.0 for WordPress and Dotclear suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 9e1279300ac5f76d0b6725e54d3abd554b6b664d9dd441e1e078f9adebdb376f
Secunia Security Advisory 44395
Posted May 4, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two security issues and two vulnerabilities have been discovered in the Magazeen theme for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service).

tags | advisory, denial of service, vulnerability, xss
SHA-256 | aadef2cbe2bf6bc033df7bac91e74c1699291db7f57b4817d8ab06d6ec104094
Joomla Themes Cross Site Scripting / Denial Of Service
Posted Apr 24, 2011
Authored by MustLive

Multiple Joomla themes suffer from cross site scripting, denial of service, disclosure, and abuse of functionality vulnerabilities.

tags | exploit, denial of service, vulnerability, xss
SHA-256 | 8148583b8ad762681628eac607ff239001cef718fb344300b322e5c939626ba1
Secunia Security Advisory 44275
Posted Apr 21, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two security issues and two vulnerabilities have been reported in WooThemes Bueno, City Guide, Coffee Break, Daily Edition, Delegate, Fresh News, Headlines, Inspire, Optimize, Over Easy, and The Station ExpressionEngine themes, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service).

tags | advisory, denial of service, vulnerability, xss
SHA-256 | 56adfd5fea63167983051b1869f7693780828dcbb7e2a6893b95bf628381f594
Secunia Security Advisory 44235
Posted Apr 19, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two security issues and two vulnerabilities have been reported in the Mimbo Pro theme for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service).

tags | advisory, denial of service, vulnerability, xss
SHA-256 | 0364300f70a2b40fd120c325e694068e5b7e359f3a97dc2c64d0337ea7b7a46d
Drupal Themes XSS / Denial Of Service
Posted Apr 18, 2011
Authored by MustLive

Multiple Drupal themes suffer from cross site scripting and denial of service vulnerabilities. Affected themes include Fresh News, Inspire, Spectrum, Delegate, Optimize, Bueno, Headlines, Daily Edition, Coffee Break, The Gazette Edition.

tags | advisory, denial of service, vulnerability, xss
SHA-256 | 165887f15d9354eaf9b8d1bb945cb0dc9da0684b19cf44be05684f5b05d60ae6
Secunia Security Advisory 44140
Posted Apr 17, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two security issues and two vulnerabilities have been reported in WooThemes Live Wire and Gazette Edition WordPress themes, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service).

tags | advisory, denial of service, vulnerability, xss
SHA-256 | 72057db40a756fe535209523780c1e7c91f7b97dec73c31f0a2b8d6ddaa52b2a
The Gazette Edition Cross Site Scripting
Posted Apr 11, 2011
Authored by MustLive

The Gazette Edition (theme for WordPress) versions 2.9.4 and below suffer from cross site scripting, denial of service, path disclosure and abuse of functionality vulnerabilities.

tags | exploit, denial of service, vulnerability, xss
SHA-256 | 554e2b12eb7acbe0808897d2e279223beeade9555f821b00b156e5c83a058674
Live Wire 2.3.1 XSS / Disclosure / Denial Of Service
Posted Apr 8, 2011
Authored by MustLive

Live Wire Edition theme version 2.3.1 for WordPress suffers from cross site scripting, denial of service, path disclosure and abuse of functionality vulnerabilities.

tags | exploit, denial of service, vulnerability, xss
SHA-256 | 79b89bb2c36ba7e839e6894861693e23d1bfac75cb85db1f03d2104a7ce96832
Secunia Security Advisory 43547
Posted Mar 19, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in the SimpleDark theme for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | 38a3f881dc643cfe82c0db71e55c5788c2ea5bed737e0ed9856cbd40cd763f36
Zero Day Initiative Advisory 10-290
Posted Dec 15, 2010
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 10-290 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of SAP NetWeaver Business Client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the Load and LoadTheme methods of the SapThemeRepository ActiveX control (sapwdpcd.dll) implemented by SAP NetWeaver Business Client. Due to a failure in bounds checking, a user-supplied parameter supplied to the vulnerable methods can overflow a stack buffer resulting in arbitrary code execution under the context of the user running the browser.

tags | advisory, remote, overflow, arbitrary, code execution, activex
SHA-256 | 3ff07756f5b8556d59a4b7213aa9a522b1fbb579894c4abd3efccb174e669381
Secunia Security Advisory 41916
Posted Oct 21, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Ubuntu Drupal Theme - Brown theme for Drupal, which can be exploited by malicious people to disclose potentially sensitive information.

tags | advisory
systems | linux, ubuntu
SHA-256 | fef4fc5938921b422ac42399f8642583a8be8896de913baf369695e4574891cf
Secunia Security Advisory 40245
Posted Jun 28, 2010
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in the Studio Theme Pack module for Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | aadb060e282a30867bd7a117c61e5b329c3372743751593a9ae21f636612d376
eFront Cross Site Scripting
Posted Jun 4, 2010
Authored by Mohammed Boumediane | Site vupen.com

VUPEN Web Vulnerability Research Team discovered multiple vulnerabilities in eFront. These issues are caused by input validation errors when processing the "remote_theme", "name", "system_email", "password_length", "math_server", "site_motto" and "site_name" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site. Versions prior to 3.6.3 build 7400 are affected.

tags | advisory, web, arbitrary, vulnerability, xss
SHA-256 | 1104801d6660f352341d2255e224ec704f33018e832b6a8a32964aa0a77e692e
Joomla YOOOtheme Cross Site Scripting
Posted Dec 7, 2009
Authored by andresg888 | Site bl4ck-p0rtal.org

The Joomla YOOOtheme component suffers from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 97eae37014fc2225afedb44591561a89fbbae53eae8be987ffeb7be18f5800e6
Secunia Security Advisory 37518
Posted Dec 7, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - andresg888 has reported a vulnerability in the YOOtheme template for Joomla, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | 35eeb59760d44a6af1c17ef3e1606eacbd294de3d5f33c2b3f22ce9fb8179e6c
Secunia Security Advisory 37334
Posted Nov 16, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in the RootCandy theme for Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | 35ee6ce9fa65d470ce6809a7b2b8c067d391aab33227cd021c903dafb323012b
Secunia Security Advisory 34080
Posted Feb 27, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Justin C. Klein Keane has discovered a vulnerability in the Taxonomy Theme module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

tags | advisory
SHA-256 | ead1ad43993c0d93f291ead88037371f7eee738851c2e3397555fc2a49aa9a81
Drupal Taxonomy Theme Cross Site Scripting
Posted Feb 26, 2009
Authored by Justin C. Klein Keane

The Drupal Taxonomy Theme version 5.x-1.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 910abd62192a62f24e88bd8e0a24cfaaf8cb8214622ef3b378fdbaa2fffeb0a0
Page 3 of 4
Back1234Next

File Archive:

December 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    11 Files
  • 2
    Dec 2nd
    0 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close