Section: .. / 0703-exploits /
| /// File Name: |
SIAADV-07-004-EN.txt |
Description:
|
Cypherstrust Ironmail version 6.1.1 suffers from multiple cross site scripting flaws.
| | Author: | Javier Olascoaga | | Homepage: | http://www.514.es/ | | File Size: | 39106 | | Last Modified: | Mar 26 23:37:01 2007 |
| MD5 Checksum: | 3b3768d0834a8ee29a4733566a784fee |
|
| /// File Name: |
CORE-2007-0219.txt |
Description:
|
Core Security Technologies Advisory - The OpenBSD kernel contains a memory corruption vulnerability in the code that handles IPv6 packets. Exploitation of this vulnerability can result in remote execution of arbitrary code at the kernel level on the vulnerable systems and/or a remote denial of service condition. Affected systems include OpenBSD 4.1 prior to Feb. 26th, 2006, OpenBSD 4.0 Current, OpenBSD 4.0 Stable, OpenBSD 3.9, OpenBSD 3.8, OpenBSD 3.6, and OpenBSD 3.1. Proof of concept exploit included.
| | Author: | Alfredo Ortega, Mario Vilas, Gerardo Richarte | | Homepage: | http://www.coresecurity.com/corelabs/ | | File Size: | 18563 | | Related CVE(s): | CVE-2007-1365 | | Last Modified: | Mar 13 22:56:29 2007 |
| MD5 Checksum: | f37a6332b213078f5620d3413f0db749 |
|
| /// File Name: |
frontbase427-remote.txt |
Description:
|
Frontbase for Windows versions 4.2.7 and below remote buffer overflow exploit.
| | Author: | Heretic2 | | File Size: | 18490 | | Last Modified: | Mar 26 23:19:20 2007 |
| MD5 Checksum: | 2dd2b3895cf5dc506f3fcd41b359b669 |
|
| /// File Name: |
warftp165-remote.txt |
Description:
|
WarFTP version 1.65 USER remote buffer overflow exploit with multiple targets.
| | Author: | niXel | | File Size: | 15505 | | Last Modified: | Mar 26 23:18:19 2007 |
| MD5 Checksum: | 74117f1ed75029e75605afba67fb4e15 |
|
| /// File Name: |
dnsfun.c |
Description:
|
Exploiting Microsoft DNS dynamic updates for fun and profit.
| | Author: | Andres Tarasco | | Homepage: | http://www.514.es/ | | File Size: | 15378 | | Last Modified: | Mar 23 21:16:31 2007 |
| MD5 Checksum: | 6c4af2bef05d82e19d8cb3a3912fd004 |
|
| /// File Name: |
netrekfs.zip |
Description:
|
Proof of concept exploit for Netrek versions 2.12.0 and below which suffer from a format string vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | netrekfs.txt | | File Size: | 14409 | | Last Modified: | Mar 8 17:26:41 2007 |
| MD5 Checksum: | 7d0fda35161f28a0a988a3bae5206b7a |
|
| /// File Name: |
npds-exec.txt |
Description:
|
Net Portal Dynamic System (NPDS) versions 5.10 and below remote code execution exploit.
| | Author: | DarkFig | | Homepage: | http://www.acid-root.new.fr/ | | File Size: | 8849 | | Last Modified: | Mar 20 11:22:55 2007 |
| MD5 Checksum: | 1dce29ddb8906e6662ec1afd9f300077 |
|
| /// File Name: |
php-importreqvar.txt |
Description:
|
PHP versions greater than or equal to 4.0.7 and less than or equal to 5.2.1 suffer from an arbitrary variable overwrite in import_request_variables().
| | Author: | Stefano di Paola, Francesco Ongaro | | Homepage: | http://www.wisec.it/ | | File Size: | 8343 | | Last Modified: | Mar 8 22:25:31 2007 |
| MD5 Checksum: | 7caa19415b07b0f1e5e2e58ca201d09d |
|
| /// File Name: |
Advisory2-24012007.txt |
Description:
|
PhpMyAdmin versions 2.9.2 and below suffer from cross site scripting and cross site request forgery flaws.
| | Author: | AlFa | | Homepage: | http://www.virtuax.be/ | | File Size: | 8232 | | Last Modified: | Mar 8 21:28:44 2007 |
| MD5 Checksum: | 74a320204d81438afaf88dc1f55d7263 |
|
| /// File Name: |
newsreactor-2.txt |
Description:
|
NewsReactor 20070220 article grabbing remote buffer overflow exploit. Version 2.
| | Author: | Marsu | | File Size: | 8085 | | Last Modified: | Mar 19 23:55:14 2007 |
| MD5 Checksum: | 83e617ba02b413f48ca2840ca1c50933 |
|
| /// File Name: |
wp13exp.c |
Description:
|
Corel Worperfect X3 version 13.0.0.565 suffers from a stack overflow vulnerability. Exploit included.
| | Author: | Jonathan So | | Homepage: | http://www.nop-art.net/ | | File Size: | 7756 | | Last Modified: | Mar 29 02:21:41 2007 |
| MD5 Checksum: | 8cece6f324de927d4cdfd1da2451acc5 |
|
| /// File Name: |
BTP00001P005CF.zip |
Description:
|
Proof of concept exploit for Comodo Firewall Pro. Comodo Firewall Pro (former Comodo Personal Firewall) stores some of its internal settings in the registry key HKLM\SYSTEM\Software\Comodo\Personal Firewall. This key is protected by Comodo drivers such that other applications are not able to change the settings. This protection can be bypassed if very special conditions are met.
| | Homepage: | http://www.matousec.com/ | | Related File: | comodo-bypass.txt | | File Size: | 7577 | | Last Modified: | Mar 6 00:23:55 2007 |
| MD5 Checksum: | c0c0d78228e1b55c482155fe750e5f2b |
|
| /// File Name: |
dproxy-v1.c |
Description:
|
Remote exploit for dproxy versions 0.5 and below. Binds a shell to TCP port 4444.
| | Author: | mu-b | | File Size: | 7068 | | Last Modified: | Apr 2 18:35:30 2007 |
| MD5 Checksum: | 52c1dcd14162b2cc97262976b36f2700 |
|
| /// File Name: |
snort-dos.txt |
Description:
|
Snort versions 2.6.1.1, 2.6.1.2, and 2.7.0 remote denial of service exploit.
| | Author: | Antimatt3r | | File Size: | 6957 | | Last Modified: | Mar 8 21:36:08 2007 |
| MD5 Checksum: | 6e20a13f424102045efa3174b98dae4b |
|
| /// File Name: |
wpl3exp.c |
Description:
|
Unavailable.
| | File Size: | 6947 | | Last Modified: | Mar 29 02:00:56 2007 |
| MD5 Checksum: | bb438bd88d41e2d4c4cd779e6fe61413 |
|
| /// File Name: |
caid-msgeng.txt |
Description:
|
CA BrightStor ARCserve remote stack overflow exploit that takes advantage of msgeng.exe.
| | Author: | Winny Thomas | | File Size: | 6766 | | Last Modified: | Mar 19 23:59:23 2007 |
| MD5 Checksum: | 1388521454aee2669c9a327a37223708 |
|
| /// File Name: |
NukeSentinel-sql.txt |
Description:
|
NukeSentinel versions 2.5.06 and below SQL injection exploit for use with mysql versions 4.0.24 and above.
| | Author: | DarkFig | | Homepage: | http://www.acid-root.new.fr/ | | File Size: | 6743 | | Last Modified: | Mar 13 20:41:03 2007 |
| MD5 Checksum: | bf37e57e370ad5fbb9632dc3aea56b31 |
|
| /// File Name: |
newsreactor-1.txt |
Description:
|
NewsReactor 20070220 article grabbing remote buffer overflow exploit. Version 1.
| | Author: | Marsu | | File Size: | 6720 | | Last Modified: | Mar 19 23:54:30 2007 |
| MD5 Checksum: | 85b9587feb6b8f81204e286c3f19f316 |
|
| /// File Name: |
aig-mssql.txt |
Description:
|
Absolute Image Gallery version 2.0 MS-SQL injection exploit that makes use of Gallery.ASP.
| | Author: | UniquE-Key | | File Size: | 6631 | | Last Modified: | Mar 20 01:11:37 2007 |
| MD5 Checksum: | 981577bb3461453ed8495f9677a39a2c |
|
| /// File Name: |
woltlab236-xss.txt |
Description:
|
Woltlab version 2.3.6 appears susceptible to cross site scripting vulnerabilities.
| | Author: | Samenspender | | File Size: | 6585 | | Last Modified: | Mar 6 03:55:24 2007 |
| MD5 Checksum: | cfb07028d27d24d80fc678a4c7ba4501 |
|
| /// File Name: |
helix-1101.txt |
Description:
|
Helix Server version 11.0.1 remote heap overflow exploit for win2k SP4. Binds a shell to tcp/4444.
| | Author: | Winny Thomas | | File Size: | 6501 | | Last Modified: | Mar 21 21:52:13 2007 |
| MD5 Checksum: | 4140b638e2cfb7b688f74fa64985f9a7 |
|
| /// File Name: |
etherleak.txt |
Description:
|
Ethernet device drivers frame padding information leakage exploit.
| | Author: | Jon Hart | | Homepage: | http://spoofed.org/ | | File Size: | 5938 | | Last Modified: | Mar 23 21:07:03 2007 |
| MD5 Checksum: | 83295a72d9cd10f46c8027056b53b40a |
|
|
|
|
|