Section: .. / 0804-exploits /
| /// File Name: |
runcmsmyartcles-sql.txt |
Description:
|
The RunCMS MyArticles module version 0.6 Beta-1 suffers from a remote SQL injection vulnerability.
| | Author: | Cr@zy_King | | File Size: | 603 | | Last Modified: | Apr 28 11:02:21 2008 |
| MD5 Checksum: | a33acd308ffd65afd399f138f07ad7b5 |
|
| /// File Name: |
phpforge-sql.txt |
Description:
|
PHP Forge versions 3 beta 2 and below suffer from a remote SQL injection vulnerability.
| | Author: | jiko | | Homepage: | http://www.no-back.org/ | | File Size: | 1035 | | Last Modified: | Apr 28 11:01:23 2008 |
| MD5 Checksum: | fff61f7e24feed2e08db6001c669dcaf |
|
| /// File Name: |
postnukefg-sql.txt |
Description:
|
The PostNuke pnFlashGames module versions 2.5 and below suffer from multiple SQL injection vulnerabilities.
| | Author: | Kacper | | Homepage: | http://devilteam.pl/ | | File Size: | 1839 | | Last Modified: | Apr 28 11:00:26 2008 |
| MD5 Checksum: | b0a0092214667a64d2ee08329d7f4aa0 |
|
| /// File Name: |
clevercopy-sql.txt |
Description:
|
Clever Copy version 3.0 suffers from a SQL injection vulnerability in postview.php.
| | Author: | U238 | | Homepage: | http://noexec.blogspot.com/ | | File Size: | 1421 | | Last Modified: | Apr 28 10:59:12 2008 |
| MD5 Checksum: | 6e2b5bd1b495e5e5df8c7b523fb685f6 |
|
| /// File Name: |
angeloemlak-multi.txt |
Description:
|
Angelo-Emlak version 1.0 suffers from cross site scripting and SQL injection vulnerabilities.
| | Author: | U238 | | Homepage: | http://noexec.blogspot.com/ | | File Size: | 1654 | | Last Modified: | Apr 28 10:57:12 2008 |
| MD5 Checksum: | 4f87281171374796515448d55b2fdb35 |
|
| /// File Name: |
siteman2x-multi.txt |
Description:
|
Siteman 2.x suffers from code execution, cross site scripting, and local file inclusion vulnerabilities.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 3304 | | Last Modified: | Apr 28 10:54:55 2008 |
| MD5 Checksum: | 4055f4092c00541bbea7e308d4e82b18 |
|
| /// File Name: |
joomlavisites-rfi.txt |
Description:
|
Joomla Visites version 1.1 RC2 suffers from a remote file inclusion vulnerability.
| | Author: | NoGe | | File Size: | 2037 | | Last Modified: | Apr 28 10:53:37 2008 |
| MD5 Checksum: | 048fc13e3584d9f256dc84913f4606ce |
|
| /// File Name: |
kantaris-overflow.txt |
Description:
|
Kantaris version 0.3.4 media player local buffer overflow exploit. Creates a film.ssa file and upon successful exploitation binds a shell to port 4444.
| | Author: | j0rgan | | Homepage: | http://www.jorgan.users.cg.yu/ | | File Size: | 4179 | | Last Modified: | Apr 25 20:03:08 2008 |
| MD5 Checksum: | 4b7836ddbca8f4c532518e3da2d34f13 |
|
| /// File Name: |
minibb-xsssql.txt |
Description:
|
miniBB version 2.2 suffers from cross site scripting and SQL injection vulnerabilities.
| | Author: | __GiReX__ | | Homepage: | http://girex.altervista.org/ | | File Size: | 3238 | | Last Modified: | Apr 25 11:50:13 2008 |
| MD5 Checksum: | 2f24be5cc164dd06af2312166b0a53f6 |
|
| /// File Name: |
postnukeschedule-sql.txt |
Description:
|
The Postnuke PostSchedule module suffers from a SQL injection vulnerability.
| | Author: | Kacper | | Homepage: | http://devilteam.pl/ | | File Size: | 396 | | Last Modified: | Apr 25 11:48:46 2008 |
| MD5 Checksum: | df6ab270461e2067aaba18641133a4e2 |
|
| /// File Name: |
lotus-exec.txt |
Description:
|
Lotus Symphony Expeditor suffers from an arbitrary code execution vulnerability via the handling of URIs with rcplauncher.
| | Author: | Thomas Pollet | | File Size: | 605 | | Last Modified: | Apr 24 16:33:34 2008 |
| MD5 Checksum: | 75febdef7a73a4c6e21c145294d9f0ff |
|
| /// File Name: |
joomlajpad-sql.txt |
Description:
|
The Joomla Jpad component version 1.0 suffers from a SQL injection vulnerability.
| | Author: | His0k4 | | File Size: | 1239 | | Last Modified: | Apr 24 16:16:21 2008 |
| MD5 Checksum: | d19044c095683d24f39446363319e738 |
|
| /// File Name: |
divx-Exploit.cpp.txt |
Description:
|
DivX Player versions 6.7 and below .SRT subtitle parsing exploit. Spawns calc.exe.
| | Author: | Luong Anh Hoang | | File Size: | 4268 | | Last Modified: | Apr 24 16:15:39 2008 |
| MD5 Checksum: | 37d09fac44506ded108e7ed7c1f9e49e |
|
| /// File Name: |
PR07-44.txt |
Description:
|
RSA Authentication Agent is vulnerable to a vanilla cross site scripting flaw on the login page. Tested on RSA Authentication Agent 5.3.0.258 for Web for Internet Information Services.
| | Homepage: | http://www.procheckup.com/ | | File Size: | 7634 | | Last Modified: | Apr 23 20:50:44 2008 |
| MD5 Checksum: | 235b73c9ce5e7d2b972b90fb6dc75713 |
|
| /// File Name: |
PR07-43.txt |
Description:
|
A HTML injection vulnerability exists in the WebLogic administration console. Version 10.0 is susceptible. remote URI redirection vulnerability affects the RSA Authentication Agent. This issue is due to a failure of the application to properly sanitize URI-supplied data assigned to the 'url' parameter. Tested on RSA Authentication Agent 5.3.0.258 for Web for Internet Information Services in conjunction with Mozilla Firefox 2.0.0.11.
| | Author: | Richard Brain | | Homepage: | http://www.procheckup.com/ | | File Size: | 3630 | | Last Modified: | Apr 23 20:49:12 2008 |
| MD5 Checksum: | ddc424c80bd593c395ae868dd66bb6e6 |
|
| /// File Name: |
joomlaprofiler-sql.txt |
Description:
|
The Joomla Profiler component is susceptible to a blind SQL injection vulnerability.
| | Author: | $hur!k'n | | File Size: | 824 | | Last Modified: | Apr 23 20:47:08 2008 |
| MD5 Checksum: | eacb279cfeaca40e231660078aecf4a9 |
|
| /// File Name: |
youtubeclone-exec.txt |
Description:
|
YouTube Clone Script remote code execution exploit that makes use of spages.php.
| | Author: | Inphex | | File Size: | 9524 | | Last Modified: | Apr 23 20:45:48 2008 |
| MD5 Checksum: | ac115a8046e28aedc28b0e54b7b0ff7a |
|
| /// File Name: |
joomlafiliale-sql.txt |
Description:
|
The Joomla Filiale component version 1.0.4 suffers from a SQL injection vulnerability in index.php.
| | Author: | str0xo | | Homepage: | http://www.dz-h4ck3rz.com/ | | File Size: | 1199 | | Last Modified: | Apr 23 12:55:39 2008 |
| MD5 Checksum: | 717fcfe481664a7f1331b395f3efebc8 |
|
| /// File Name: |
webcal-sql.txt |
Description:
|
Web Calendar versions 4.1 and below blind SQL injection exploit.
| | Author: | t0pp8uzz | | File Size: | 1505 | | Last Modified: | Apr 23 12:54:24 2008 |
| MD5 Checksum: | e2eeea398987da35bec690489639c266 |
|
| /// File Name: |
wpspreadsheet-sql.txt |
Description:
|
The WordPress Spreadsheet plugin version 0.6 and below suffer from a SQL injection vulnerability.
| | Author: | 1ten0.0net1 | | Homepage: | http://forum.antichat.ru/ | | File Size: | 770 | | Last Modified: | Apr 23 12:53:39 2008 |
| MD5 Checksum: | 4fb17cf2df5204d7a5b526a2de8c7371 |
|
| /// File Name: |
ereserv-sql.txt |
Description:
|
E RESERV version 2.1 suffers from a SQL injection vulnerability in index.php.
| | Author: | jiko | | Homepage: | http://www.no-back.org/ | | File Size: | 914 | | Last Modified: | Apr 23 12:52:24 2008 |
| MD5 Checksum: | fca39cfd25541c3a59c33287253c84a9 |
|
| /// File Name: |
hordemail-xss.txt |
Description:
|
Horde Webmail suffers from a cross site scripting vulnerability in addevent.php.
| | Author: | The-0utl4w | | Homepage: | http://aria-security.net/ | | File Size: | 428 | | Last Modified: | Apr 23 12:35:29 2008 |
| MD5 Checksum: | 5129c67ee60de010009a7b2910b1942c |
|
|
|
|
|