exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 18 of 18 RSS Feed

Files

Online Shopping Alphaware 1.0 SQL Injection
Posted Aug 5, 2020
Authored by Edo Maland

Online Shopping Alphaware version 1.0 suffers from multiple remote SQL injection vulnerabilities. Original discovery of SQL injection in this version attributed to Ahmed Abbas.

tags | exploit, remote, vulnerability, sql injection
SHA-256 | 29690f5dffee752bc5e1e472253d5ff5db429877767d895fee54163ae1c8708e

Related Files

OSAS Traverse Extension 11 Unquoted Service Path
Posted Mar 22, 2021
Authored by Tech Johnny

OSAS Traverse Extension 11 suffers from an unquoted service path vulnerability.

tags | exploit
SHA-256 | d5081a005413b7ff934e790a93aaa7906a70d3ca77ff852d52e8fdde8298e802
Alphaware E-Commerce System 1.0 Shell Upload / SQL Injection
Posted Mar 16, 2021
Authored by Christian Vierschilling

Alphaware E-Commerce System version 1.0 suffers from unauthenticated remote shell upload and remote SQL injection vulnerabilities.

tags | exploit, remote, shell, vulnerability, sql injection
SHA-256 | fbecea6b0c82b953bb75a6982c2fca7d4e938869ab5be9cbc4582b315ab49413
Online Shopping Alphaware 1.0 Unauthorized Administrative Access
Posted Aug 6, 2020
Authored by Edo Maland

Online Shopping Alphaware version 1.0 suffers from an unauthorized administrative functionality access vulnerability.

tags | exploit, bypass
SHA-256 | af86f3f2c3fc65a797a7322c542028b83b7c440ae34c67c40b6fb9d42a4d9386
Online Shopping Alphaware 1.0 Arbitrary File Upload
Posted Aug 6, 2020
Authored by Edo Maland

Online Shopping Alphaware version 1.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
SHA-256 | 1c73f02370cfc464f48e9e0329d3295cf79cee55b8d21245f13bb4fa92008374
Online Shopping Alphaware 1.0 Cross Site Request Forgery
Posted Aug 6, 2020
Authored by Edo Maland

Online Shopping Alphaware version 1.0 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 10eaf91c2386843e5718ae708a9128ff7150df99808d437a21dbbd1290208453
Online Shopping Alphaware 1.0 Cross Site Scripting
Posted Aug 5, 2020
Authored by Edo Maland

Online Shopping Alphaware version 1.0 suffers from multiple persistent cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 1bbd55c9f9e0edcb7f2d29d71a1388c6c031345adc68213198dff08b8c072b7f
Online Shopping Alphaware 1.0 Insecure Direct Object Reference
Posted Aug 5, 2020
Authored by Edo Maland

Online Shopping Alphaware version 1.0 suffers from an insecure direct object reference vulnerability.

tags | exploit
SHA-256 | 06b278a300b523b0abcc50b71dc25166b714ca2a8134c022619a39fdd096f1a0
Online Shopping Alphaware 1.0 SQL Injection
Posted Jul 31, 2020
Authored by Ahmed Abbas

Online Shopping Alphaware version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | c9c9c9485eca29f72f51a446d9758fd84d888d3463396be08d55e65155981fca
Oracle Virtual Server Agent Local Privilege Escalation
Posted Nov 3, 2010
Site onapsis.com

Onapsis Security Advisory - The Oracle Virtual Server Agent suffers from a local privilege escalation vulnerability. By exploiting this vulnerability, an authenticated attacker would be able to remotely compromise the OVS server, together with all the virtual machines configured on it. This would result in the compromise of integrity, availability and confidentiality of every virtual machine deployed in the OVS server.

tags | advisory, local
advisories | CVE-2010-3584
SHA-256 | 8bb07a17e1151edee2f97edcaff919d8ae30d080f8d6e3f3cd95c2a984839665
Oracle Virtual Server Agent Remote Command Execution
Posted Nov 3, 2010
Site onapsis.com

Onapsis Security Advisory - The Oracle Virtual Server Agent suffers from a remote command execution vulnerability. By exploiting this vulnerability, an authenticated attacker would be able to remotely compromise the OVS server, together with all the virtual machines configured on it. This would result in the compromise of integrity, availability and confidentiality of every virtual machine deployed in the OVS server.

tags | advisory, remote
advisories | CVE-2010-3583
SHA-256 | a7e7a0a5a37917b5c9d115d98333345e4e229747d1d9e70e3b2a2a9b4885be88
Oracle Virtual Server Agent Arbitrary File Access
Posted Nov 3, 2010
Site onapsis.com

Onapsis Security Advisory - The Oracle Virtual Server Agent suffers from an arbitrary file access vulnerability. By exploiting this vulnerability, an authenticated attacker would be able to remotely compromise the OVS server, together with all the virtual machines configured on it. This would result in the compromise of integrity, availability and confidentiality of every virtual machine deployed in the OVS server.

tags | advisory, arbitrary
advisories | CVE-2010-3585
SHA-256 | d031200543b4d11ba73fe8cdf870bdda3a8d6e288280d3b250bea767e3fe6228
SAP Management Console Multiple Denial Of Service
Posted Sep 29, 2010
Site onapsis.com

Onapsis Security Advisory - The SAP MC component fails to process malformed requests, resulting in a denial of service condition due to the fact that the affected service is crashed.

tags | advisory, denial of service
SHA-256 | ec64dcf534979b2047279fc6c153b6276b068cd99aebe7db61d1d4e1c851b4ca
SAP J2EE Web Services Navigator Cross Site Scripting
Posted Jul 21, 2010
Site onapsis.com

Onapsis Security Advisory - The SAP J2EE Engine contains a Web Services Navigator interface, which enables the interaction with the deployed Web Services in the server. This interface suffers from a Cross-Site Scripting vulnerability, which may enable malicious parties to perform different kind of attacks over SAP users.

tags | advisory, web, xss
SHA-256 | 8dc2a56391e65f55d9d9b2fedc38db6025320a0ec26c72f748583efc85727820
SAP J2EE Telnet Administration Security Check Bypass
Posted Jun 17, 2010
Site onapsis.com

SAP J2EE Telnet Administration suffers from an authentication bypass vulnerability.

tags | advisory, bypass
SHA-256 | 1a80e20e80a3c1db1a6e588e5955e080382df05484aa9d8c7c179a6d923eec1d
SAP J2EE Engine MDB Path Traversal
Posted Feb 12, 2010
Site onapsis.com

Onapsis Security Advisory - The Message-Driven Bean Example application in the SAP J2EE Engine suffers from a path traversal vulnerability, which may enable remote attackers to access sensitive files in the server filesystem.

tags | advisory, remote
SHA-256 | 56c2759f5a5395466ea0430458e765fc8c5964df18ac2d688fd40e06ead19690
SAP J2EE Authentication Phishing Vector
Posted Feb 12, 2010
Site onapsis.com

Onapsis Security Advisory - The Authentication mechanism of the SAP J2EE Engine (which is shared by the Enterprise Portal and other solutions) suffers from a phishing vector vulnerability, which may allow a remote attacker to perform different attacks to the organization's SAP users.

tags | advisory, remote
SHA-256 | 1cb2ce7956efa6260341088406256bfdfee382787854d2d01097084af316806b
SAP WebDynpro Runtime XSS/CSS Injection
Posted Feb 12, 2010
Site onapsis.com

Onapsis Security Advisory - SAP WebDynPro suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 9d48719f814da197b6bccfd0a7fd3e0631c617593a3bd21587145058a1d90bbf
osa-rfi.txt
Posted Feb 6, 2008
Authored by Trancek

OpenSiteAdmin versions 0.9.1.1 and below suffer from multiple remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, code execution, file inclusion
SHA-256 | 40bbe74570d048d429056d0c1a17fda85bc1e944fbaa129886682ca5af5ac6f4
Page 1 of 1
Back1Next

File Archive:

September 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    2 Files
  • 2
    Sep 2nd
    21 Files
  • 3
    Sep 3rd
    0 Files
  • 4
    Sep 4th
    17 Files
  • 5
    Sep 5th
    34 Files
  • 6
    Sep 6th
    29 Files
  • 7
    Sep 7th
    11 Files
  • 8
    Sep 8th
    25 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    26 Files
  • 12
    Sep 12th
    23 Files
  • 13
    Sep 13th
    17 Files
  • 14
    Sep 14th
    22 Files
  • 15
    Sep 15th
    16 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    19 Files
  • 19
    Sep 19th
    60 Files
  • 20
    Sep 20th
    23 Files
  • 21
    Sep 21st
    15 Files
  • 22
    Sep 22nd
    8 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close