what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 131 RSS Feed

Files

moodle16dev.txt
Posted Nov 12, 2005
Authored by rgod | Site retrogod.altervista.org

Moodle versions 1.6dev and below suffer from blind SQL injection, remote command execution, and cross site scripting flaws. Exploitation details provided.

tags | exploit, remote, xss, sql injection
SHA-256 | 7f4da795f3eca350bb006c6a9bdefe5528867b9c78c28be1d0b94852b70ca941
susechfn.sh.txt
Posted Nov 10, 2005
Authored by Hunger

Local root exploit for chfn under SuSE Linux 9.{1,2,3}/10.0, Desktop 1.0, UnitedLinux 1.0, and SuSE Linux Enterprise Server {8,9}.

tags | exploit, local, root
systems | linux, suse
SHA-256 | d6f60a4c747ccc20d91eb071b663dd492f8bab5c73280fa823a145e795a28096
fsigk_exp.py.txt
Posted Nov 10, 2005
Authored by xavier | Site xavsec.blogspot.com

F-Secure Internet Gatekeeper for Linux local root exploit written in Python.

tags | exploit, local, root, python
systems | linux
SHA-256 | a7d56ff4e5c5d57e8e6bee5a056b1b22243cc46266d105e8b2eb6fa7df25a0d7
sudo168p10.sh.txt
Posted Nov 10, 2005
Authored by breno

Local root exploit for sudo versions below 1.6.8p10 that makes use of the environment cleaning flaws with the SHELLOPTS and PS4 variables.

tags | exploit, local, root
advisories | CVE-2005-2959
SHA-256 | 01540d7b6b0b6ee45a0878ef444900d18cdc75c2444c243cfc128279fd8df1b5
0004.txt
Posted Nov 10, 2005
Site moritz-naumann.com

Antville version 1.1 suffers from a cross site scripting flaw.

tags | exploit, xss
advisories | CVE-2005-3530
SHA-256 | 65a13345a6370cbd83ef8303e92c2f6af6db5ae09e9fa12c4473aa0ad5bf627d
0003.txt
Posted Nov 10, 2005
Site moritz-naumann.com

TikiWiki versions 1.9.x up to and including 1.9.2 suffer from a cross site scripting vulnerability and possible SQL injection vulnerabilities.

tags | exploit, vulnerability, xss, sql injection
advisories | CVE-2005-3528, CVE-2005-3529
SHA-256 | 789603d9c715231cce4f6b651dd6544281cef61c96ee4a15e4b6dada3144cd12
Hardened-PHP Project Security Advisory 2005-21.80
Posted Nov 9, 2005
Authored by Christopher Kunz, Hardened-PHP Project | Site hardened-php.net

PHPKIT versions 1.6.1 R2 and below suffer from cross site scripting, SQL injection, information disclosure, password hash disclosure, local file disclosure, and arbitrary code execution flaws. Various sample exploitation details provided.

tags | exploit, arbitrary, local, code execution, xss, sql injection, info disclosure
SHA-256 | a91e4d42b773ee597b5ea0162d7a64232a6a053f5d7b8e1af72709197633e2f8
atutor151pl2.txt
Posted Nov 8, 2005
Authored by rgod | Site retrogod.altervista.org

ATutor versions less than or equal to 1.5.1pl2 SQL Injection and Remote commands execution exploit.

tags | exploit, remote, sql injection
SHA-256 | e2a2e37dcb0eaeb0884b07d1a427904fe82c1ec628e6e89d964624ea93406cd7
oste1.0.txt
Posted Nov 8, 2005
Authored by khc

The OSTE toplist script v1.0 is vulnerable to remote code execution.

tags | exploit, remote, code execution
SHA-256 | 7c98c5711a922879c1be02daa2cdaf33d7adfb1dc923a86f065747dbfbbfa609
guestbook-2.2.txt
Posted Nov 8, 2005
Authored by bhs_team | Site Babol-Hackers.com

Guestbook v2.2 is vulnerable to a classic SQL admin bypass vulnerability.

tags | exploit, bypass
SHA-256 | 834d6fd178742f363d14a0ce587fa6b9fdbeb3016c3bfafa4ee1f15cde133da3
SEC-20051107-1.txt
Posted Nov 8, 2005
Authored by Bernhard Mueller | Site sec-consult.com

SEC-CONSULT Security Advisory 20051107-1 - SEC Consult has found that parameters to ActionDefineFunction (ACTIONRECORD 0x9b) in the Macromedia Flash Plugin are not properly sanitized. Loading a specially crafted SWF leads to an improper memory access condition which can be used to crash flash player or may be exploited as a vector for code execution. This issue is similar to CVE-2005-2628 (as reported by eEye Digital Security on November 4, 2005) but affects a different function. Versions affected: flash.ocx 7.0.19.0 and earlier, libflashplayer.so before 7.0.25.0.

tags | exploit, code execution
SHA-256 | 8e6fb046a48b15f155e81ed751344b5482c9f52a4be9ea7157fd0da5cedddaa6
SEC-20051107-0.txt
Posted Nov 8, 2005
Authored by Bernhard Mueller | Site sec-consult.com

SEC-CONSULT Security Advisory 20051107-0 - toendaCMS allows for theft of CMS usernames and passwords (XML database mode), session theft (XML database mode), directory traversal attacks (XML database mode), and arbitrary file uploads. Versions below 0.6.2 are affected.

tags | exploit, arbitrary, file upload
SHA-256 | 144222686022b8b1399ddb13787fcc507b4e08544d5c7ae39a117d7c50b31914
namesXSS.txt
Posted Nov 8, 2005
Authored by reuben.31

names.co.uk, an English registrar and web hosting company, has an cross site scripting vulnerability allowing injection of arbitrary Javascript.

tags | exploit, web, arbitrary, javascript, xss
SHA-256 | 6cd18e600b100ec54795e80d0e317b9b89700aa71f5874e4be0cf2489246d22b
twiki20030201.pl.txt
Posted Nov 8, 2005
Authored by rUnViRuS | Site worlddefacers.net

TWiki 20030201 VIEW string remote command execution exploit.

tags | exploit, remote
SHA-256 | ffd1fb66748fb194d52e0c5a6b688695dcb044946458aaff1efc4b59ca8671c9
phpfm.txt
Posted Nov 8, 2005
Authored by rUnViRuS | Site worlddefacers.net

PHPFM is susceptible to a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | 48f148c2eb51c34a455f4c215f8a0d436968ee1ec6a93c978ec65d4d82ffa96d
200511-asterisk.txt
Posted Nov 8, 2005
Authored by Adam Pointon | Site assurance.com.au

A vulnerability in the voicemail retrieval system for the Asterisk PBX software allows an authenticated user to download any .wav/.WAV file from the system, including other users' voicemail messages. Versions affected: Asterisk versions 1.0.9 and below, Asterisk Beta versions 1.2.0-beta1 and below, Asterisk @ Home versions 1.5 and below, and Asterisk @ Home Beta versions 2.0 Beta 4 and below.

tags | exploit
SHA-256 | f7a5df0e22275c8fdebf7ed2d4e110a0ea24464a098ba12734cae3db12a6c84b
prdelka-vs-BSD-ptrace.tar.gz
Posted Nov 8, 2005
Authored by prdelka | Site prdelka.blackart.org.uk

NetBSD versions 2.1 and below ptrace() local root exploit.

tags | exploit, local, root
systems | netbsd
SHA-256 | e206abdb40eb38c1a16aff4226d7394d290524b17f83c8baa92a4a7a2137452e
ipb.2.1-english.txt
Posted Nov 8, 2005
Authored by Benjilenoob | Site redkod.org

Invision Power Board version 2.1 is susceptible to javascript injection and cross site scripting attacks. English version of this advisory translated by Jerome Athias. Exploitation details provided.

tags | exploit, javascript, xss
SHA-256 | 8b1b5097ef20b451fcda26afa6d66afb1521d2ef736c3cb1b0b83a5a13cd856d
x_dtsuids.pl.txt
Posted Nov 8, 2005
Authored by Charles Stevenson

Solaris 10 DtPrintinfo/Session exploit for x86.

tags | exploit, x86
systems | solaris
SHA-256 | fcc0583f608dfa2ff466ab8443bc545a183459bdd2c5ce5d9e65723a7cbcc153
ibProArcade.txt
Posted Nov 8, 2005
Authored by bhfh01

The ibProArcade module versions 2.x that are commonly used in vBulletin and Invision Power board software are susceptible to SQL injection flaws. Details provided.

tags | exploit, sql injection
SHA-256 | 79f6de0e272f1bf830d4ffd79965f9fea2316cfd146983744ef724d2c014a1cf
zoomblogJS.txt
Posted Nov 8, 2005
Authored by sikikmail

Zoomblog is prone to javascript injection attacks due to a lack of properly sanitized IMG tags.

tags | exploit, javascript
SHA-256 | 3ea5e379559a4c91c8b4af83e3904c8e6abcb6a6c8d1d02c1c63f05366da9649
phpWebThings144.txt
Posted Nov 8, 2005
Authored by Linux_Drox | Site lezr.com

phpWebThings versions 1.4.4 is susceptible to cross site scripting and SQL injection attacks. Detail provided.

tags | exploit, xss, sql injection
SHA-256 | 703c649fd4ad3bf5f3b8dfb16bfab0686e4f8735856badd8942182440e2629fe
lnxFTPDssl_warez.c
Posted Nov 8, 2005
Authored by Kingcope

linux-ftpd-ssl version 0.17 remote root exploit.

tags | exploit, remote, root
systems | linux
SHA-256 | be5cea73ef109d7b131805238e4fdeaedde07aca071a5fe50ad0772a3753c056
xmbforums.txt
Posted Nov 8, 2005
Authored by HACKERS PAL

XMB Forums is susceptible to cross site scripting attacks in u2u.php.

tags | exploit, php, xss
SHA-256 | bbb2a654df6ab03046d51ea118cf72c911fff98877b83dcfa0f05269f1984584
ipb.2.1.txt
Posted Nov 8, 2005
Authored by Benjilenoob | Site redkod.org

Invision Power Board version 2.1 is susceptible to javascript injection and cross site scripting attacks. Advisory is in French. Exploitation details provided.

tags | exploit, javascript, xss
SHA-256 | f9a96e4c9b10a0a99733b83955e71987b9af50073119af556a7a942b0e758e2d
Page 4 of 6
Back23456Next

Top Authors In Last 30 Days

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close