Section: .. / 0608-exploits /
| /// File Name: |
securityXSS.txt |
Description:
|
Multiple security vendors suffers from cross site scripting flaws.
| | Author: | Thomas Pollet | | File Size: | 459 | | Last Modified: | Aug 18 01:05:08 2006 |
| MD5 Checksum: | a79ce8dc976b46084ae16fb5f0c83575 |
|
| /// File Name: |
dconnx.zip |
Description:
|
Exploit that demonstrates a buffer overflow, null pointer, and various format string bugs in DConnect Daemon versions 0.7.0 and below and CVS versions 30 and below.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | dconnx.txt | | File Size: | 8630 | | Last Modified: | Aug 18 00:59:40 2006 |
| MD5 Checksum: | 40d7652d078da822e6f2d7a21b547448 |
|
| /// File Name: |
sicherheit_286.txt |
Description:
|
NEWSolved Lite version 1.9.2 suffers from a remote file inclusion vulnerability.
| | Author: | Philipp Niedziela | | File Size: | 1363 | | Last Modified: | Aug 18 00:55:22 2006 |
| MD5 Checksum: | 57b2fd9c52e4cdf0050b838b86d61f77 |
|
| /// File Name: |
solpot-adv-05.txt |
Description:
|
phpCC Beta 4.2 suffers from a remote file inclusion vulnerability.
| | Author: | Solpot | | Homepage: | http://www.solpotcrew.org/ | | File Size: | 2243 | | Last Modified: | Aug 18 00:46:47 2006 |
| MD5 Checksum: | cd3f606cd5016ad01c528fc3615c552f |
|
| /// File Name: |
iecrash.tgz |
Description:
|
Microsoft Internet Explorer crashes when refreshing an iframe containing an XML file with an XSL stylesheet. Examples included.
| | Author: | Thomas Pollet | | File Size: | 2296 | | Last Modified: | Aug 18 00:46:03 2006 |
| MD5 Checksum: | c21a03eb2dc6a64fb232eecaa3707cfd |
|
| /// File Name: |
XennoBB.txt |
Description:
|
XennoBB versions 2.1.0 and below suffer from a SQL injection vulnerability.
| | Author: | Chris Boulton | | Homepage: | http://www.surfionline.com/ | | File Size: | 1440 | | Last Modified: | Aug 18 00:41:52 2006 |
| MD5 Checksum: | 72f74731cf8cf313d84d3fe467622ee4 |
|
| /// File Name: |
brush.txt |
Description:
|
WMF proof of concept denial of service exploit that causes a page fault in gdi32!CreateBrushIndirect().
| | Author: | cyanid-E | | File Size: | 1173 | | Last Modified: | Aug 18 00:19:01 2006 |
| MD5 Checksum: | f739cecc99a2ab0edc3b607c1d9c6041 |
|
| /// File Name: |
jp-wiki.txt |
Description:
|
JD-Wiki suffers from a remote file inclusion vulnerability.
| | Author: | hackbsd crew | | File Size: | 765 | | Last Modified: | Aug 18 00:16:52 2006 |
| MD5 Checksum: | ae5edacc6e920825f1aa763bde216be4 |
|
| /// File Name: |
mybloggie214.txt |
Description:
|
MyBloggie versions 2.1.4 and below trackback.php SQL injection exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 7871 | | Last Modified: | Aug 18 00:13:35 2006 |
| MD5 Checksum: | 94e784034c074ddf8ef6c107983cc9c9 |
|
| /// File Name: |
PHPCodeCabinet.txt |
Description:
|
All versions of PHPCodeCabinet are susceptible to a remote file inclusion flaw.
| | Author: | Minion | | File Size: | 1202 | | Last Modified: | Aug 17 23:48:57 2006 |
| MD5 Checksum: | a194bb36a4cacf70cdaa2368375aee2b |
|
| /// File Name: |
lesstif-advisory.pdf |
Description:
|
Lesstif local root exploit for Mandrake Linux 2006 that makes use of the mtink binary which is setuid by default.
| | Author: | Karol Wiesek | | Homepage: | http://karol.wiesek.pl/ | | File Size: | 43724 | | Last Modified: | Aug 17 23:47:58 2006 |
| MD5 Checksum: | dab61de17ed00b1aceccf8b0697fe42e |
|
| /// File Name: |
phpLocal.txt |
Description:
|
PHP versions 5.1.4 and below and 4.4.3 and below suffer from a local buffer underflow that can allow for arbitrary code execution. Proof of concept exploit included.
| | Author: | Heintz | | File Size: | 4513 | | Last Modified: | Aug 17 23:43:41 2006 |
| MD5 Checksum: | 1cf6294d4dcb59ca2db90df97e8b2c97 |
|
| /// File Name: |
sicherheit_83.txt |
Description:
|
phpAutoMembersArea version 3.2.5 suffers from a remote file inclusion vulnerability.
| | Author: | Philipp Niedziela | | File Size: | 1596 | | Last Modified: | Aug 17 23:41:36 2006 |
| MD5 Checksum: | 0d6f4265be77fe53a2b3d71cec81a66b |
|
| /// File Name: |
barracudaExec.txt |
Description:
|
Lack of input sanitization in the Linux based Barracuda spam firewall web interface allows execution of commands by unauthenticated users. Combined with privilege elevation techniques, execution of commands as the root user is possible allowing a full system compromise.
| | Author: | Matthew Hall | | Related Exploit: | barracudeArbitrary.txt | | File Size: | 4808 | | Last Modified: | Aug 17 23:35:33 2006 |
| MD5 Checksum: | 3b6e67d632c2e90b0cf3ae0f045713d8 |
|
| /// File Name: |
zonex103.txt |
Description:
|
ZoneX version 1.0.3 suffers from a remote file inclusion vulnerability.
| | Author: | x0r0n | | File Size: | 630 | | Last Modified: | Aug 17 04:57:51 2006 |
| MD5 Checksum: | 11a51bc61720c5a66ecbc6b59938412a |
|
| /// File Name: |
MEDS13.txt |
Description:
|
ME Download System version 1.3 suffers from a remote file inclusion vulnerability.
| | Author: | Philipp Niedziela | | File Size: | 1661 | | Last Modified: | Aug 17 04:56:02 2006 |
| MD5 Checksum: | 3e2344cc0facc392f360190dbba59bc3 |
|
| /// File Name: |
BlogCMS.txt |
Description:
|
Blog:CMS versions 4.1.0 and below suffer from a remote file inclusion flaw.
| | Author: | Drago84 | | File Size: | 734 | | Last Modified: | Aug 17 04:47:22 2006 |
| MD5 Checksum: | 3c9c7ca4bfa05ac4b95fc5056e1cb058 |
|
| /// File Name: |
solpot-adv-04.txt |
Description:
|
modernbill version 1.6 suffers from a remote file inclusion vulnerability.
| | Author: | Solpot | | Homepage: | http://www.solpotcrew.org/ | | File Size: | 1911 | | Last Modified: | Aug 17 04:32:56 2006 |
| MD5 Checksum: | c22b29bcfa687e711824c1bd92121af4 |
|
| /// File Name: |
sendcard_340_xpl.txt |
Description:
|
SendCard version 3.4.0 and below unauthorized administrative access and remote command execution exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 10652 | | Last Modified: | Aug 17 04:28:44 2006 |
| MD5 Checksum: | 852dd392e9403399436b28dda514bada |
|
| /// File Name: |
vwarXSSSQL.txt |
Description:
|
Vwar version 1.5.0 and below suffer from SQL injection and cross site scripting flaws.
| | Author: | MFox | | Homepage: | http://www.hackerz.ir | | File Size: | 541 | | Last Modified: | Aug 17 04:22:27 2006 |
| MD5 Checksum: | f0d7e0b86cdc276e416e7351f6c57005 |
|
| /// File Name: |
OZJournal15.txt |
Description:
|
OZJournal version 1.5 suffers from a cross site scripting vulnerability.
| | Author: | luny | | File Size: | 1305 | | Last Modified: | Aug 17 04:12:12 2006 |
| MD5 Checksum: | 9f978f0032aa1c31f9bc70b10d5b4998 |
|
| /// File Name: |
mircServerexploitXPSP1.c |
Description:
|
Proof of concept exploit that takes advantage of a buffer overflow in the /server directive of mIRC versions 6.17 and below. In a default install, this does not elevate privileges.
| | Author: | Jordi Corrales | | File Size: | 2169 | | Last Modified: | Aug 17 04:02:27 2006 |
| MD5 Checksum: | a80c103dc0069ce2b620733db87ac00c |
|
| /// File Name: |
saveweb34.txt |
Description:
|
SaveWeb Portal version 3.4 suffers from a remote file inclusion vulnerability.
| | Author: | x0r0n | | File Size: | 714 | | Last Modified: | Aug 17 04:00:24 2006 |
| MD5 Checksum: | 0a3d64c6adcec8f70c996a16d31240db |
|
|
|
|
|