Section: .. / 0707-exploits /
| /// File Name: |
vrnews-bypass.txt |
Description:
|
VRNews version 1.x suffers from a remote permission bypass vulnerability in admin.php.
| | Author: | R4M! | | File Size: | 303 | | Last Modified: | Jul 7 00:41:02 2007 |
| MD5 Checksum: | fcf3aca675e5da00274caf4bae70563c |
|
| /// File Name: |
netflow-xss.txt |
Description:
|
The NetFlow Analyzer version 5 and the OpManager version 7 suffer from cross site scripting vulnerabilities.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 10529 | | Last Modified: | Jul 7 00:26:29 2007 |
| MD5 Checksum: | ca73d8db88c2e0c22a0e76be0bfc735f |
|
| /// File Name: |
fujitsu-primergy-disclose.txt |
Description:
|
RedTeam Pentesting discovered an information disclosure in the Fujitsu-Siemens BX300 Switch Blade during a penetration test. By accessing URLs of the web interface directly and aborting the authentication dialog, one is able to access the restricted management interface without proper authentication, having read-only access.
| | Homepage: | http://www.redteam-pentesting.de/ | | File Size: | 5139 | | Related CVE(s): | CVE-2007-3012 | | Last Modified: | Jul 7 00:23:27 2007 |
| MD5 Checksum: | 272d316eed89893d1a54824e03924143 |
|
| /// File Name: |
saphpshowcat-sql.txt |
Description:
|
Saphp suffers from a SQL injection vulnerability.
| | Author: | Sw33t h4cK3r | | File Size: | 140 | | Last Modified: | Jul 7 00:14:34 2007 |
| MD5 Checksum: | aedde5af0c70052ab227bba3bca38e23 |
|
| /// File Name: |
saphplessonshow-sql.txt |
Description:
|
SaphpLesson version 2.0 suffers from a SQL injection vulnerability.
| | Author: | Sw33t h4cK3r | | File Size: | 140 | | Last Modified: | Jul 7 00:14:01 2007 |
| MD5 Checksum: | cd9742b2ff308ecb88ef6c429d52306c |
|
| /// File Name: |
pnphpbb2view-sql.txt |
Description:
|
PNphpBB2 versions 1.2i and below remote SQL injection exploit that makes use of viewforum.php.
| | Author: | Coloss | | File Size: | 7885 | | Last Modified: | Jul 6 23:39:17 2007 |
| MD5 Checksum: | 599095a3b3fff637ac31d1dc297f19b8 |
|
| /// File Name: |
girlserv-sql.txt |
Description:
|
Girlserv ads version 1.5 and below suffer from a SQL injection vulnerability in details_news.php.
| | Author: | Cold z3ro | | Homepage: | http://www.hack-teach.com/ | | File Size: | 1151 | | Last Modified: | Jul 6 23:36:25 2007 |
| MD5 Checksum: | b8fe8a06f810a6c459b9efbd678d1309 |
|
| /// File Name: |
supercali-sql.txt |
Description:
|
SuperCali PHP Event Calendar version 0.4.0 suffers from a SQL injection vulnerability.
| | Author: | t0pp8uzz, xprog | | File Size: | 1020 | | Last Modified: | Jul 6 23:35:26 2007 |
| MD5 Checksum: | 7e0d5006fe6e9826cb4b0bab68442a9a |
|
| /// File Name: |
esri-overflow.txt |
Description:
|
ESRI ArcSDE version 9.0 through 9.2sp1 remote buffer overflow exploit.
| | Author: | Heretic2 | | File Size: | 26527 | | Last Modified: | Jul 6 23:33:46 2007 |
| MD5 Checksum: | b9e77931f9ce0e636782a2e784b6d2f3 |
|
| /// File Name: |
axis-camcontrol.txt |
Description:
|
AXIS Camera Control remote buffer overflow exploit that makes use of AxisCamControl.ocx version 1.0.2.15.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 3156 | | Last Modified: | Jul 6 23:32:52 2007 |
| MD5 Checksum: | 9e04d3b23191d0e24ad8153a942ba515 |
|
| /// File Name: |
olms-xss.txt |
Description:
|
The web-based Oliver Library Management System is susceptible to cross site scripting vulnerabilities.
| | Author: | A. R. | | File Size: | 1632 | | Last Modified: | Jul 6 23:29:22 2007 |
| MD5 Checksum: | f16c04565b67f0ef64c0d0d2fe38c5a0 |
|
| /// File Name: |
moodle-xss.txt |
Description:
|
Moodle suffers from a cross site scripting vulnerability in index.php.
| | Author: | MustLive | | File Size: | 1033 | | Last Modified: | Jul 6 22:43:58 2007 |
| MD5 Checksum: | 84c56dfe433f6cfea1822a59febcc783 |
|
| /// File Name: |
avarcade-admin.txt |
Description:
|
AV Arcade version 2.1b suffers from a administrative escalation issue via cookie manipulation.
| | Author: | Kw3rLn | | Homepage: | http://rst-crew.net/ | | File Size: | 619 | | Last Modified: | Jul 2 20:53:50 2007 |
| MD5 Checksum: | 6f1010348edb2d87b5a3e241e08fe8c9 |
|
| /// File Name: |
yoggie-exec.txt |
Description:
|
The Yoggie Pico Pro security appliance suffers from a remote code execution vulnerability.
| | Author: | Cody Brocious | | File Size: | 2145 | | Last Modified: | Jul 2 20:15:07 2007 |
| MD5 Checksum: | c11ac66079a64477d6eda3c71009ef03 |
|
| /// File Name: |
vbzoom1x-sql.txt |
Description:
|
vbzoom version 1.x suffers from a remote SQL injection vulnerability in forum.php.
| | Author: | Cold z3ro | | Homepage: | http://www.hack-teach.com/ | | File Size: | 2186 | | Last Modified: | Jul 2 19:48:47 2007 |
| MD5 Checksum: | dfadb6cc73d6a4652099969277927166 |
|
| /// File Name: |
phpdirector-sql.txt |
Description:
|
PHP Director versions 0.21 and below suffers from a remote SQL injection vulnerability in videos.php.
| | Author: | Kw3rLn | | Homepage: | http://rst-crew.net/ | | File Size: | 1434 | | Last Modified: | Jul 2 19:47:21 2007 |
| MD5 Checksum: | 739e45c804d7bf2dc6c138fdedd342cb |
|
| /// File Name: |
avarcade-sql.txt |
Description:
|
AV Arcade version 2.1b suffers from a remote SQL injection vulnerability.
| | Author: | Kw3rLn | | Homepage: | http://rst-crew.net/ | | File Size: | 438 | | Last Modified: | Jul 2 19:42:49 2007 |
| MD5 Checksum: | 529ae354e1e15411c0a6e1b243cf1735 |
|
| /// File Name: |
youtube-sql.txt |
Description:
|
The YouTube Clone script suffers from a remote SQL injection vulnerability in msg.php.
| | Author: | t0pp8uzz, xprog | | File Size: | 1297 | | Last Modified: | Jul 2 19:41:23 2007 |
| MD5 Checksum: | 7242bb9cbfd41fa7bd87c0bc37fa45e7 |
|
| /// File Name: |
hpinstat-overflow.txt |
Description:
|
HP Instant Support remote buffer overflow exploit. Tested on Windows XP Professional SP2 full patched with IE7.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 1212 | | Last Modified: | Jul 2 19:40:06 2007 |
| MD5 Checksum: | 410b6307253c901df3d3b8863a30ff30 |
|
| /// File Name: |
efendy-xss.txt |
Description:
|
Efendy Blog version 1.0 suffers from a cross site scripting vulnerability.
| | Author: | GeFORC3 | | Homepage: | http://WwW.GeFORC3.Org | | File Size: | 744 | | Last Modified: | Jul 2 19:35:26 2007 |
| MD5 Checksum: | fa30d4467d0dcaa1b347710b8792e1ae |
|
| /// File Name: |
gorki-xss.txt |
Description:
|
Gorki Online Santra? Sitesi suffers from a cross site scripting vulnerability.
| | Author: | GeFORC3 | | Homepage: | http://WwW.GeFORC3.Org | | File Size: | 1036 | | Last Modified: | Jul 2 19:34:59 2007 |
| MD5 Checksum: | 33f5273930f122a44d9f77c19884c432 |
|
| /// File Name: |
phpeventcal-sql.txt |
Description:
|
phpEventCalendar version 0.2.2 suffers from a remote SQL injection vulnerability in eventdisplay.php.
| | Author: | Iron | | Homepage: | http://ironwarez.info/ | | File Size: | 1101 | | Last Modified: | Jul 1 17:16:48 2007 |
| MD5 Checksum: | 654ff1289b7adcfd6b55f24815c1a5ae |
|
|
|
|
|