Section: .. / 0602-exploits /
| /// File Name: |
xmame-sploits.txt |
Description:
|
Proof of concept exploits in both C and Perl that demonstrate the existence of the local vulnerability found in Xmame version 0.102.
| | Author: | Rafael San Miguel Carrasco | | File Size: | 1463 | | Last Modified: | Feb 2 06:09:29 2006 |
| MD5 Checksum: | 6e5acd34e4318ff1b9f901aaf1f47c75 |
|
| /// File Name: |
PHPClassifieds.txt |
Description:
|
PHP Classifieds version 6.2 and lower suffer from an authentication bypass vulnerability.
| | Author: | Audun Larsen | | File Size: | 1438 | | Last Modified: | Feb 14 18:38:14 2006 |
| MD5 Checksum: | aee4bd6d2912e9bc74b9c164000f48b0 |
|
| /// File Name: |
vuSQL.pl.txt |
Description:
|
Simple perl exploit that makes use of a flaw in VU Site Engine version 2.0 that allows for unauthenticated addition of administrative users.
| | Author: | GeW, censored | | Homepage: | http://www.security.nitro.ru | | File Size: | 1414 | | Last Modified: | Feb 25 22:59:07 2006 |
| MD5 Checksum: | 75085f71818bbd10217bebbaf1a3d5ac |
|
| /// File Name: |
UebiMiauXSS.txt |
Description:
|
UebiMiau version 2.7.9 is susceptible to cross site scripting attacks.
| | Author: | M.Neset KABAKLI | | Homepage: | http://www.wakiza.com | | File Size: | 1410 | | Last Modified: | Feb 1 21:02:24 2006 |
| MD5 Checksum: | 8d6e33609ec1f7f788c61bf903b4d7e1 |
|
| /// File Name: |
icqmailXSS.txt |
Description:
|
ICQmail.com and Mail2World.com suffer from cross site scripting flaws.
| | Author: | nukedx | | Homepage: | http://www.nukedx.com | | File Size: | 1333 | | Last Modified: | Feb 25 23:58:29 2006 |
| MD5 Checksum: | c3fee6f7605d4b6c0b0ed69706cf3e4e |
|
| /// File Name: |
ipswitch_dos.txt |
Description:
|
IPSwitch WhatsUp Professional 2006 is susceptible to a denial of service condition. Details provided.
| | Author: | Josh Zlatin-Amishav | | File Size: | 1330 | | Last Modified: | Feb 25 20:37:45 2006 |
| MD5 Checksum: | aac876847b84a06fa4cdc5291afbe90d |
|
| /// File Name: |
EV0063.txt |
Description:
|
PHP Event Calendar 1.5 - Username and Password isn't sanitized before being written to users.php file. This can be used to make XSS attack or corrupt users data.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1325 | | Last Modified: | Feb 16 19:26:14 2006 |
| MD5 Checksum: | b9ac17e3028d212dc7f424f400ca09eb |
|
| /// File Name: |
EV0062.txt |
Description:
|
2200net Calendar system suffers from multiple SQL injection vulnerabilities.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1322 | | Last Modified: | Feb 16 19:23:04 2006 |
| MD5 Checksum: | 0a9791706c8a56746112303c8e86533b |
|
| /// File Name: |
saphplesson.pl.txt |
Description:
|
SaphpLesson version 2.0 remote SQL injection exploit.
| | Author: | SnIpEr_SA | | File Size: | 1312 | | Last Modified: | Feb 26 00:17:11 2006 |
| MD5 Checksum: | 5ac4708a3b589768e21f0f412b7c4513 |
|
| /// File Name: |
farsiInclusion.txt |
Description:
|
FarsiNews versions 2.1 and below suffer from a remote file inclusion vulnerability.
| | Author: | Hamid Ebadi | | Homepage: | http://hamid.ir/security | | File Size: | 1303 | | Last Modified: | Feb 2 06:00:10 2006 |
| MD5 Checksum: | 9c475f3fd5fe557762169d53553da102 |
|
| /// File Name: |
EV0073.txt |
Description:
|
Magic Downloads 1.1.3 allows untrusted users to make changes to config.php.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1289 | | Last Modified: | Feb 22 14:44:28 2006 |
| MD5 Checksum: | d5a391cbd20fe4750602836d4ea98074 |
|
| /// File Name: |
VCardLITE-2.4.txt |
Description:
|
The default installation of VCardLITE does not remove install.php leading to remote code execution.
| | Author: | disruptor | | File Size: | 1266 | | Last Modified: | Feb 13 04:58:52 2006 |
| MD5 Checksum: | 20935c52523feda376b3c35386e27b9b |
|
| /// File Name: |
ashnewsXSS.txt |
Description:
|
ashnews version 0.83 is susceptible to cross site scripting attacks.
| | Author: | 0o_zeus_o0 | | Homepage: | http://www.olimpusklan.org | | File Size: | 1249 | | Last Modified: | Feb 2 05:25:58 2006 |
| MD5 Checksum: | 3bb089c91f3c446b2fffcd73ce4fed29 |
|
| /// File Name: |
NSAG-200-24.02.2006.txt |
Description:
|
NSA Group Advisory - The ArGoSoft Mail Server Pro version 1.8 IMAP server suffers from improper input validation when RENAME is being used.
| | Homepage: | http://www.nsag.ru/ | | File Size: | 1238 | | Last Modified: | Feb 25 23:25:20 2006 |
| MD5 Checksum: | 548ffc621afef361e0a99b7389eb5ece |
|
| /// File Name: |
woltlabbb2xXSS.txt |
Description:
|
Woltlab Burning Board 2.x is susceptible to multiple cross site scripting flaws. Details provided.
| | Author: | nukedx | | Homepage: | http://www.nukedx.com | | File Size: | 1226 | | Last Modified: | Feb 25 23:39:52 2006 |
| MD5 Checksum: | 420c3e636135a43dce33fd16c785df0a |
|
| /// File Name: |
rubronegrodotnet.txt |
Description:
|
www.rubronegro.net is susceptible to cross site scripting and SQL injection attacks.
| | Author: | Rephumos | | File Size: | 1215 | | Last Modified: | Feb 25 22:34:19 2006 |
| MD5 Checksum: | 4f5151d022a964fa9621ec82b683f9f2 |
|
| /// File Name: |
EV0055.txt |
Description:
|
Unknown Domain Shoutbox version 2005.07.21 is susceptible to multiple SQL injection and cross site scripting vulnerabilities.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1211 | | Related CVE(s): | CVE-2006-0605, CVE-2006-0606 | | Last Modified: | Feb 13 01:10:22 2006 |
| MD5 Checksum: | 183418831c7b514797a5229f17b16a2c |
|
| /// File Name: |
EV0080.txt |
Description:
|
M. Blom HTML::BBCode perl module XSS Vulnerabilities
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1125 | | Last Modified: | Feb 16 19:20:33 2006 |
| MD5 Checksum: | 0c6e2d799ff7d38b9c443e2f58a19e69 |
|
| /// File Name: |
NSAG-201-25.02.2006.txt |
Description:
|
NSA Group Advisory - SPiD version 1.3.1 suffers from a classic directory traversal flaw.
| | Homepage: | http://www.nsag.ru/ | | File Size: | 1107 | | Last Modified: | Feb 25 23:55:19 2006 |
| MD5 Checksum: | fb2c7f7b0a9e482e7b6e02404373198e |
|
| /// File Name: |
EV0079.txt |
Description:
|
My Blog 1.63 suffers from XSS in the BBcode url and img tags.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1095 | | Last Modified: | Feb 16 19:19:07 2006 |
| MD5 Checksum: | daaa40c2e87b6753ca9c103281f1e9d1 |
|
|
|
|
|