Section: .. / 0703-exploits /
| /// File Name: |
newsreactor-1.txt |
Description:
|
NewsReactor 20070220 article grabbing remote buffer overflow exploit. Version 1.
| | Author: | Marsu | | File Size: | 6720 | | Last Modified: | Mar 19 23:54:30 2007 |
| MD5 Checksum: | 85b9587feb6b8f81204e286c3f19f316 |
|
| /// File Name: |
php-rgod.txt |
Description:
|
PHP versions 4.4.6 and below ibase_connect() local buffer overflow exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 845 | | Last Modified: | Mar 19 23:53:19 2007 |
| MD5 Checksum: | f0e961972d3501dc8c8d3ef5deaf0ada |
|
| /// File Name: |
MOPB-header.txt |
Description:
|
Month of PHP Bugs - PHP version 5.2.0 header() space trimming buffer underflow exploit for Mac OSX.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 5720 | | Last Modified: | Mar 19 23:52:05 2007 |
| MD5 Checksum: | 020cb1bd1853cb779242b530d6ed5e88 |
|
| /// File Name: |
MOPB-array.txt |
Description:
|
Month of PHP Bugs - PHP versions 4.4.6 and below and versions 5.2.1 and below array_user_key_compare() ZVAL dtor local exploit.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 2141 | | Last Modified: | Mar 19 23:51:12 2007 |
| MD5 Checksum: | 2b2f9a995cd86df7beef003693c26d99 |
|
| /// File Name: |
MOPB-session.txt |
Description:
|
Month of PHP Bugs - PHP versions 5.2.1 and below session_regenerate_id() double free exploit.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 4877 | | Last Modified: | Mar 19 23:49:56 2007 |
| MD5 Checksum: | 48e53dccc2178903d16399e0be0afbea |
|
| /// File Name: |
MOPB-rejected.txt |
Description:
|
Month of PHP Bugs - PHP version 5.2.0 and 5.2.1 rejected session ID double free exploit.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 4985 | | Last Modified: | Mar 19 23:48:20 2007 |
| MD5 Checksum: | fa807de95020d193a5171e7f2767ab3a |
|
| /// File Name: |
MOPB-extfilter.txt |
Description:
|
Month of PHP Bugs - PHP version 5.2.0 ext/filter space trimming buffer underflow exploit for Mac OSX.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 5689 | | Last Modified: | Mar 19 23:47:23 2007 |
| MD5 Checksum: | 2734e29c6a46f88cf87331885a1505bd |
|
| /// File Name: |
MOPB-fdf.txt |
Description:
|
Month of PHP Bugs - PHP versions 5.2.0 and below ext/filter FDF post filter bypass exploit.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 1874 | | Last Modified: | Mar 19 23:46:08 2007 |
| MD5 Checksum: | 7232a87f3e1275ce8ec773d3f141c2a5 |
|
| /// File Name: |
MOPB-pecl.txt |
Description:
|
Month of PHP Bugs - PHP 5.2.0 / PHP with PECL ZIP versions 1.8.3 and below zip:// URL wrapper buffer overflow exploit.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 2087 | | Last Modified: | Mar 19 23:45:03 2007 |
| MD5 Checksum: | 468df0fbc65fafe91d72325e58cc6be4 |
|
| /// File Name: |
MOPB-substr.txt |
Description:
|
Month of PHP Bugs - PHP versions 5.2.1 and below substr_compare() information leak exploit.
| | Author: | Stefan Esser | | Homepage: | http://hardened-php.net/ | | File Size: | 2251 | | Last Modified: | Mar 19 23:43:44 2007 |
| MD5 Checksum: | b2efdaa1b725567a0f643cf70c74cd32 |
|
| /// File Name: |
netvios-sql.txt |
Description:
|
NetVios Portal suffers from a remote SQL injection vulnerability in page.asp.
| | Author: | parad0x | | File Size: | 610 | | Last Modified: | Mar 19 23:40:59 2007 |
| MD5 Checksum: | 78f91175fb1f356cab04b5e407070d11 |
|
| /// File Name: |
minerva-sql.txt |
Description:
|
phpBB Minerva Mod versions 2.0.21 and below suffer from a SQL injection vulnerability.
| | Author: | xoron | | File Size: | 643 | | Last Modified: | Mar 19 23:40:17 2007 |
| MD5 Checksum: | 67a1de6e2e32a161f5f1d78458211804 |
|
| /// File Name: |
phpnukesplat-lfi.txt |
Description:
|
PHP-Nuke Module splattforum version 4.0 RC1 local file inclusion exploit.
| | Author: | GolD_M | | File Size: | 3612 | | Last Modified: | Mar 19 23:38:44 2007 |
| MD5 Checksum: | b6f39bdeec9aec87be98aeefc75f3c28 |
|
| /// File Name: |
metaforum-upload.txt |
Description:
|
MetaForum versions 0.513_beta and below remote file upload exploit.
| | Author: | Gu1ll4um3r0m41n | | File Size: | 4654 | | Last Modified: | Mar 19 23:37:39 2007 |
| MD5 Checksum: | 156de2b962ef2875914e77adf403bfb7 |
|
| /// File Name: |
scriptmagix-sql.txt |
Description:
|
ScriptMagix Lyrics versions 2.0 and below index.php SQL injection exploit.
| | Author: | ajann | | File Size: | 1024 | | Last Modified: | Mar 19 23:36:19 2007 |
| MD5 Checksum: | a87176b74010a996516a7dcb91eb2bb7 |
|
| /// File Name: |
katalog-sql.txt |
Description:
|
Katalog Plyt Audio versions 1.0 and below remote SQL injection exploit.
| | Author: | Kacper | | Homepage: | http://www.rahim.webd.pl/ | | File Size: | 3060 | | Last Modified: | Mar 19 23:35:10 2007 |
| MD5 Checksum: | 385f51b972ef05e24c6e0df60e68b5a7 |
|
| /// File Name: |
wsnguest-sql.txt |
Description:
|
WSN Guest version 1.2.1 Comments.PHP SQL injection exploit.
| | Author: | UniquE-Key | | File Size: | 1726 | | Last Modified: | Mar 19 23:29:30 2007 |
| MD5 Checksum: | 24e0d298f960f2dadf84ae8e60b9f8fd |
|
| /// File Name: |
SA-20070314-0.txt |
Description:
|
SEC Consult Security Advisory 20070314-0 - If the Apache HTTP Server and Tomcat are configured to interoperate with the common proxy modules (mod_proxy, mod_rewrite, mod_jk), an attacker might be able to break out of the intended destination path up to the webroot in Tomcat.
| | Author: | D. Matscheko | | Homepage: | http://www.sec-consult.com | | File Size: | 3512 | | Related CVE(s): | CVE-2007-0450 | | Last Modified: | Mar 19 23:26:18 2007 |
| MD5 Checksum: | 5262c705a158558fe3884f0bbf91fb63 |
|
| /// File Name: |
ris-xss.txt |
Description:
|
The RIS web application used to browse Austrian laws is susceptible to cross site scripting attacks.
| | Author: | Florian Stinglmayr | | File Size: | 754 | | Last Modified: | Mar 19 23:00:32 2007 |
| MD5 Checksum: | 5f22852030112743a9c76439b166fe83 |
|
| /// File Name: |
phppos-rfi.txt |
Description:
|
PHP Point Of Sale version 1.1 for osCommerce suffers from a remote file inclusion flaw.
| | Author: | BorN To K!LL | | File Size: | 979 | | Last Modified: | Mar 19 22:53:45 2007 |
| MD5 Checksum: | 9eed4b35ebe17202fcf36396faa182be |
|
| /// File Name: |
CORE-2007-0219.txt |
Description:
|
Core Security Technologies Advisory - The OpenBSD kernel contains a memory corruption vulnerability in the code that handles IPv6 packets. Exploitation of this vulnerability can result in remote execution of arbitrary code at the kernel level on the vulnerable systems and/or a remote denial of service condition. Affected systems include OpenBSD 4.1 prior to Feb. 26th, 2006, OpenBSD 4.0 Current, OpenBSD 4.0 Stable, OpenBSD 3.9, OpenBSD 3.8, OpenBSD 3.6, and OpenBSD 3.1. Proof of concept exploit included.
| | Author: | Alfredo Ortega, Mario Vilas, Gerardo Richarte | | Homepage: | http://www.coresecurity.com/corelabs/ | | File Size: | 18563 | | Related CVE(s): | CVE-2007-1365 | | Last Modified: | Mar 13 22:56:29 2007 |
| MD5 Checksum: | f37a6332b213078f5620d3413f0db749 |
|
| /// File Name: |
vbulletin-sql.txt |
Description:
|
vBulletin suffers from a SQL injection flaw via the admin panel.
| | Author: | meto5757, disfigure | | File Size: | 782 | | Last Modified: | Mar 13 22:35:10 2007 |
| MD5 Checksum: | 042481c1835d861987d864fecce66eb1 |
|
| /// File Name: |
jgbbs-sql.txt |
Description:
|
JGBBS version 3.0beta1 Search.ASP "Author" SQL injection exploit.
| | Author: | UniquE-Key | | Homepage: | http://www.UniquE-Key.Org | | File Size: | 1738 | | Last Modified: | Mar 13 22:34:09 2007 |
| MD5 Checksum: | a0a173b66e3337563c419b5eb13a8a62 |
|
|
|
|
|