Technical Cyber Security Alert TA07-103A - A buffer overflow in the the Remote Procedure Call (RPC) management interface used by the Microsoft Windows Domain Name Service (DNS) service is actively being exploited. This vulnerability may allow a remote attacker to execute arbitrary code with SYSTEM privileges.
d2859d68d4c262fbd5b36580b848066e0110d1dde3ed78789494106b76010fda
The Virtual War module version 1.5 for PHP-Nuke suffers from cross site scripting and SQL injection vulnerabilities.
2111b2e88fd8dc025ec920603795bf88b8d9edaca68a5936d24fdc075e57c53c
MailBee WebMail Pro version 3.4 suffers from a cross site scripting vulnerability.
e0bfe7a7fab1b7303ad97ea5d5c2068c3c936e66d19e005b5725f598ba102f80
MiniShare version 1.5.4 remote denial of service exploit.
70b307f80da9050335fe8e40da058abaf226f5bff0bef5ababe7c292043d8241
Max Media Manager versions 0.1.29-rc and below and 0.3.31-alpha-pr2 and below suffer from HTTP response splitting vulnerabilities.
e45c478c078f852b6c2dffaa38f4e11272c6bb69ac0e93123533a7cb22f6a90f
Openads versions 2.0.11 and below suffers from HTTP response splitting attacks.
53403817f5a46e40bb752ec4d5b071f12971a2957d3bc49af38869f853f922b5
Acubix PicoZip version 4.02 suffers from a directory traversal vulnerability.
54755ccc748b1fae93071278d8335794f0f9a535cfeb624a7800403f01adec2b
Ettercap-NG version 0.7.3 remote denial of service exploit.
b2139ea4fc43839b6c84d260c0f5f9bec2768550e823b2a6dba42026768752e7
Whitepaper entitled "Hacking Databases For Owning Your Data". This paper goes into specifics on how to compromise MS-SQL and Oracle databases. It includes tools and exploits as well.
4f0613de36a3479fd1e5e7c57266df8715f1eb1c690eea5f55baf65e0ef90793