Section: .. / 0602-exploits /
| /// File Name: |
imageVue16.1.txt |
Description:
|
The upload script in ImageVue 16.1 does not perform proper checking, thus allowing an attacker to upload a file to any writable directory.
| | Author: | zjieb | | File Size: | 887 | | Last Modified: | Feb 13 03:54:22 2006 |
| MD5 Checksum: | ac2fd08ac3d1f1bf95a207cbda525b77 |
|
| /// File Name: |
farsiNews.txt |
Description:
|
FarsiNews versions 2.5 and below suffer from various local file inclusion and direct file access flaws.
| | Author: | Hamid Ebadi | | Homepage: | http://hamid.ir/security | | File Size: | 1991 | | Last Modified: | Feb 13 01:43:37 2006 |
| MD5 Checksum: | bca38a41aa58750435700d49091876b2 |
|
| /// File Name: |
cpaint202XSS.txt |
Description:
|
CPAINT versions 2.0.2 and below suffer from a cross site scripting flaw.
| | Homepage: | http://www.gulftech.org/ | | File Size: | 2312 | | Last Modified: | Feb 13 01:20:02 2006 |
| MD5 Checksum: | 958a02b7f621147375687639902e1cb9 |
|
| /// File Name: |
runcms_13a_xpl.html |
Description:
|
RunCMS versions 1.2 and below arbitrary remote inclusion exploit. Also allows for code execution on RunCMS versions 1.3a2 and below by making use of an upload flaw via FCKEditor.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 19460 | | Last Modified: | Feb 13 01:17:25 2006 |
| MD5 Checksum: | 41ab4e99ce769362efd908d736fd7ce0 |
|
| /// File Name: |
EV0056.txt |
Description:
|
GuestBookHost version 2005.04.25 is susceptible to an authentication bypass flaw.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1001 | | Related CVE(s): | CVE-2006-0542 | | Last Modified: | Feb 13 01:12:23 2006 |
| MD5 Checksum: | 3ab3d1ff1201c1f343fb1823c97c57f1 |
|
| /// File Name: |
EV0055.txt |
Description:
|
Unknown Domain Shoutbox version 2005.07.21 is susceptible to multiple SQL injection and cross site scripting vulnerabilities.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1211 | | Related CVE(s): | CVE-2006-0605, CVE-2006-0606 | | Last Modified: | Feb 13 01:10:22 2006 |
| MD5 Checksum: | 183418831c7b514797a5229f17b16a2c |
|
| /// File Name: |
DSR-QNX6.2.1-phfont.sh.txt |
Description:
|
Local root exploit for QNX Neutrino RTOS's phfont command. Affects QNX Neutrino RTOS version 6.2.1. Earlier versions may also be susceptible.
| | Author: | kokanin | | Homepage: | http://www.lort.dk | | Related File: | 02.07.06-2.txt | | File Size: | 616 | | Last Modified: | Feb 9 21:06:46 2006 |
| MD5 Checksum: | 671f10313114f264e395db3183a96069 |
|
| /// File Name: |
halfLifeDoS.txt |
Description:
|
Remote denial of service exploit for Half-Life engines that cause it to fall in an infinite loop and stop processing requests.
| | Author: | Firestorm | | File Size: | 1080 | | Last Modified: | Feb 9 00:06:48 2006 |
| MD5 Checksum: | 66d32b957f64c66400a685f8b6a22b1e |
|
| /// File Name: |
spip_182g_shell_inj_xpl.html |
Description:
|
SPIP versions 1.8.2g and below remote command execution exploit that makes use of an arbitrary local inclusion flaw and SQL injection.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 11464 | | Last Modified: | Feb 8 23:56:53 2006 |
| MD5 Checksum: | 66a4f913c42aa8b6ab29bec9dfa02183 |
|
| /// File Name: |
dragonfly9.0.6.1_incl_xpl.html |
Description:
|
CPGNuke Dragonfly version 9.0.6.1 remote command execution exploit that makes use of an arbitrary local inclusion flaw.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 57266 | | Last Modified: | Feb 8 23:54:04 2006 |
| MD5 Checksum: | f976ab73fdd4af3d5416535861bd7144 |
|
| /// File Name: |
whompSQL.txt |
Description:
|
Whomp Real Estate Manager XP 2005 is susceptible to SQL injection attacks.
| | Author: | Night_Warrior | | File Size: | 310 | | Last Modified: | Feb 8 23:52:08 2006 |
| MD5 Checksum: | 57726d8067dbc4a3d3c95fd29a785cce |
|
| /// File Name: |
eyeOS089.txt |
Description:
|
eyeOS versions 0.8.9 and below suffer from a remote command execution flaw.
| | Homepage: | http://www.gulftech.org/ | | File Size: | 1857 | | Last Modified: | Feb 8 00:20:50 2006 |
| MD5 Checksum: | 540a336a52918c998c078556aa64a34b |
|
| /// File Name: |
oprofile.txt |
Description:
|
OProfile versions 0.9.1 and below suffer from an insecure path vulnerability that allows for privilege escalation.
| | Author: | Luis Miguel Ferreira da Silva | | File Size: | 2343 | | Last Modified: | Feb 8 00:18:05 2006 |
| MD5 Checksum: | de21c1464c1dae6ec3fe4ad71c8e36c0 |
|
| /// File Name: |
myquiz101.pl.txt |
Description:
|
MyQuiz version 1.01 remote command execution exploit.
| | Author: | Hessam-x | | Homepage: | http://www.hessamx.net | | File Size: | 906 | | Last Modified: | Feb 8 00:13:03 2006 |
| MD5 Checksum: | 7900c395f52e9f8a89832ae176214813 |
|
| /// File Name: |
thebatSpoof.txt |
Description:
|
The design flow in the way The Bat! 2.x displays messages allows attackers to spoof RFC 822 headers and more.
| | Author: | 3APA3A | | Homepage: | http://www.security.nnov.ru/ | | File Size: | 3667 | | Last Modified: | Feb 7 23:47:26 2006 |
| MD5 Checksum: | 212fb85e01a3ee49cc29be81def5dcca |
|
| /// File Name: |
bluetooth6.c |
Description:
|
Proof of concept exploit that resets Sony/Ericsson phones via a flaw in Bluetooth.
| | Author: | Pierre BETOUIN | | File Size: | 2106 | | Last Modified: | Feb 7 23:42:23 2006 |
| MD5 Checksum: | 5acaadc7050431ec712623359c4007dd |
|
| /// File Name: |
xfocus-SD-060206.txt |
Description:
|
Test exploit to see if a BCB compiler is susceptible to an integer overflow. Versions BCB6+ent_upd4 and below are susceptible.
| | Homepage: | http://www.xfocus.org | | File Size: | 2265 | | Last Modified: | Feb 7 23:36:25 2006 |
| MD5 Checksum: | 762827aa2f720d62f47699b6bbb2a57e |
|
| /// File Name: |
ASPThai.NetGuestbook.pl.txt |
Description:
|
SQL injection exploit for ASPThai.Net Guestbook version 5.5 and possibly higher. Grabs the admin username and password.
| | Author: | MurderSkillz | | Homepage: | http://www.g00ns.net | | File Size: | 8415 | | Last Modified: | Feb 7 23:32:24 2006 |
| MD5 Checksum: | 62de4c19681588aa1608ded99424d2bf |
|
| /// File Name: |
kapda-26.txt |
Description:
|
MyTopix 1.2.3 suffers from Sql Injection and Path Disclosure vulnerabilities.
| | Author: | cvh | | Homepage: | http://www.KAPDA.ir | | File Size: | 1748 | | Last Modified: | Feb 5 23:01:39 2006 |
| MD5 Checksum: | e0a222ad9a9a548153d2e337bcf483e4 |
|
|
|
|
|