Section: .. / 0611-exploits /
| /// File Name: |
directadmin-1281.txt |
Description:
|
DirectAdmin version 1.28.1 suffers from a cross site scripting vulnerability.
| | Homepage: | http://aria-security.net/ | | File Size: | 994 | | Last Modified: | Nov 14 02:15:51 2006 |
| MD5 Checksum: | 596ccf0c0743c29d93004c2441c033b3 |
|
| /// File Name: |
mystats-108.txt |
Description:
|
MyStats version 1.0.8 and below suffer from SQL injection, cross site scripting, and path disclosure vulnerabilities.
| | Author: | laurent gaffi, benjamin moss | | Homepage: | http://s-a-p.ca/ | | File Size: | 1026 | | Last Modified: | Nov 14 02:12:16 2006 |
| MD5 Checksum: | aee6636099bb225a1ff8f6283f59a292 |
|
| /// File Name: |
storystream.txt |
Description:
|
StoryStream version 4.0 suffers from remote file inclusion vulnerabilities.
| | Author: | v1per-haCker | | Homepage: | http://www.xp10.com | | File Size: | 3502 | | Last Modified: | Nov 14 02:03:53 2006 |
| MD5 Checksum: | f9038ea8128856e2029aee807359d4d6 |
|
| /// File Name: |
phpwind-501.txt |
Description:
|
PHPWind versions 5.0.1 and below AdminUser remote blind SQL injection exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 9150 | | Last Modified: | Nov 14 02:01:55 2006 |
| MD5 Checksum: | 18e9515c184821f51140b2b519dcbe7e |
|
| /// File Name: |
ramacms068.txt |
Description:
|
Rama CMS versions 0.68 and below local file inclusion exploit.
| | Author: | Kacper | | Homepage: | http://www.rahim.webd.pl/ | | File Size: | 7729 | | Last Modified: | Nov 14 02:00:41 2006 |
| MD5 Checksum: | 71fa42e645ae38422c86778fbe0014af |
|
| /// File Name: |
contentnow-130-2.txt |
Description:
|
ContentNow version 1.30 suffers from directory traversal and cross site scripting vulnerabilities.
| | Author: | Timq | | Homepage: | http://securitydb.org/ | | File Size: | 910 | | Last Modified: | Nov 14 01:59:02 2006 |
| MD5 Checksum: | bfd4b266567da6fe861d2b11f9dbc6c7 |
|
| /// File Name: |
contentnow-130.txt |
Description:
|
ContentNow version 1.30 suffers from local file inclusion, file upload and command execution vulnerabilities.
| | Author: | r0ut3r | | File Size: | 3711 | | Last Modified: | Nov 14 01:57:36 2006 |
| MD5 Checksum: | 794cdef9f3f1d363b50f92e9eb4517da |
|
| /// File Name: |
quickcart-20.txt |
Description:
|
QuickCart versions 2.0 and below local file inclusion exploit that leverages actions_client/gallery.php.
| | Author: | Kacper | | Homepage: | http://www.rahim.webd.pl/ | | File Size: | 8482 | | Last Modified: | Nov 14 01:55:46 2006 |
| MD5 Checksum: | 93ad7b90ec3259c85490ad21e3de4d4d |
|
| /// File Name: |
r3mote_win_UDPexec.pl.txt |
Description:
|
Original Win32 version of the exploit for the gwrd bug in SAP versions below 4.6D patch 1767 and versions below 6.40 patch 4. Allows for remote command execution.
| | Author: | FX of Phenoelit | | File Size: | 1490 | | Last Modified: | Nov 14 01:52:58 2006 |
| MD5 Checksum: | 655cccf80e97da3df892dd6b0ef94ce3 |
|
| /// File Name: |
r3mote_unix_wrapper.sh.txt |
Description:
|
Linux port of the exploit for the gwrd bug in SAP versions below 4.6D patch 1767 and versions below 6.40 patch 4. Allows for remote command execution. Shell script version.
| | Author: | Nicob | | File Size: | 1346 | | Last Modified: | Nov 14 01:51:13 2006 |
| MD5 Checksum: | a1142e01a3f786842681b10d22c340b2 |
|
| /// File Name: |
r3mote_unix_UDPexec.pl.txt |
Description:
|
Linux port of the exploit for the gwrd bug in SAP versions below 4.6D patch 1767 and versions below 6.40 patch 4. Allows for remote command execution. Perl version.
| | Author: | Nicob | | File Size: | 1402 | | Last Modified: | Nov 14 01:50:29 2006 |
| MD5 Checksum: | fa38199776009325b7968543cc79e157 |
|
| /// File Name: |
sapchk.c |
Description:
|
Utility to test users and passwords with RfcOpenEx on SAP systems. Now deprecated in favor of THC Hydra.
| | Author: | Nicob | | File Size: | 3551 | | Last Modified: | Nov 14 01:48:39 2006 |
| MD5 Checksum: | c1ce68a6f324365ca84f1242f22a43cb |
|
| /// File Name: |
sap-banner.c |
Description:
|
SAP RFC_SYSTEM_INFO information disclosure exploit that leaks OS type, real IP address, SAP version, and more.
| | Author: | Nicob | | File Size: | 7357 | | Last Modified: | Nov 14 01:47:34 2006 |
| MD5 Checksum: | 96b58aa2aba723709a768cf2d891f460 |
|
| /// File Name: |
SAP_WebAS_UDP_DoS.c |
Description:
|
Two byte UDP denial of service exploit for SAP version below 6.40 patch 6.
| | Author: | Nicob | | File Size: | 6684 | | Last Modified: | Nov 14 01:45:34 2006 |
| MD5 Checksum: | 4317da203cf4470a5db5b6b1e174503c |
|
| /// File Name: |
cpanel10-xss.txt |
Description:
|
CPanel version 10 is susceptible to cross site scripting attacks via the file manager.
| | Homepage: | http://aria-security.net/ | | File Size: | 756 | | Last Modified: | Nov 14 01:26:41 2006 |
| MD5 Checksum: | feeb6ec6b27206ac9a279075e921fa0d |
|
| /// File Name: |
bib-rfi.txt |
Description:
|
The Web based bibliography management system suffers from a remote file inclusion vulnerability.
| | Author: | navairum | | File Size: | 1125 | | Last Modified: | Nov 14 01:21:57 2006 |
| MD5 Checksum: | 539bfa91cfbc047374da7cc78cd573a1 |
|
| /// File Name: |
shambo2-45.txt |
Description:
|
Shambo2 Component for Mambo version 4.5 remote file inclusion exploit.
| | Author: | Crackers_Child | | File Size: | 2707 | | Last Modified: | Nov 14 01:20:00 2006 |
| MD5 Checksum: | b8d423995da47ca3cd871d4210dd9235 |
|
| /// File Name: |
roundcube-XSS.txt |
Description:
|
Roundcube webmail appears to have a cross site scripting vulnerability.
| | Author: | RSnake | | Homepage: | http://ha.ckers.org/ | | File Size: | 702 | | Last Modified: | Nov 14 01:12:38 2006 |
| MD5 Checksum: | 68e7ace35bc9860beb5f93e75f73c88f |
|
| /// File Name: |
proppro-10.txt |
Description:
|
Property Pro version 1.0 suffers from a remote login bypass SQL injection vulnerability in vir_Login.asp.
| | Author: | ajann | | File Size: | 421 | | Last Modified: | Nov 14 01:05:25 2006 |
| MD5 Checksum: | 981306fe36493f1dc26908a1bfc24ebc |
|
| /// File Name: |
eam-13.txt |
Description:
|
Estate Agent Manager versions 1.3 and below suffer from a SQL injection vulnerability in default.asp.
| | Author: | ajann | | File Size: | 430 | | Last Modified: | Nov 14 01:04:31 2006 |
| MD5 Checksum: | b03162de534cfa20233fa72687e2f68c |
|
| /// File Name: |
onlineer-20.txt |
Description:
|
Online Event Registration versions 2.0 and below remote user password change exploit that makes use of save_profile.asp.
| | Author: | ajann | | File Size: | 1054 | | Last Modified: | Nov 14 01:03:43 2006 |
| MD5 Checksum: | 9f93b9a96d68f1bc54efb9ad14f092d9 |
|
| /// File Name: |
ASPPortal-400.txt |
Description:
|
ASPPortal versions 4.0.0 and below remote SQL injection exploit that makes use of default1.asp.
| | Author: | ajann | | File Size: | 7780 | | Last Modified: | Nov 14 01:02:56 2006 |
| MD5 Checksum: | 64efb632dfb906d4e3d6c6a242605d18 |
|
|
|
|
|