Section: .. / 0801-exploits /
| /// File Name: |
dcpportal-sql.txt |
Description:
|
DCP-Portal versions 6.11 and below remote SQL injection exploit.
| | Author: | x0kster | | File Size: | 1940 | | Last Modified: | Jan 6 20:05:02 2008 |
| MD5 Checksum: | 2771e17a68073489632fb8210a12dce5 |
|
| /// File Name: |
mailbee-insecure.txt |
Description:
|
MailBee Objects version 5.5 remote insecure method exploit that makes use of MailBee.dll.
| | Author: | darkl0rd | | File Size: | 1917 | | Last Modified: | Jan 29 21:32:48 2008 |
| MD5 Checksum: | 47633fe5819b31e22350bec36d4d5fd3 |
|
| /// File Name: |
DSECRG-08-007.txt |
Description:
|
The OpenBSD BGPD web interface on OpenBSD 4.1 suffers from a cross site scripting vulnerability.
| | Author: | Sh2kerr,Stas Svistunovich | | Homepage: | http://www.dsec.ru/ | | File Size: | 1916 | | Last Modified: | Jan 31 23:30:08 2008 |
| MD5 Checksum: | f7e06b130f3eefb98b5ad9697e94a408 |
|
| /// File Name: |
cpndrv-dos.c |
Description:
|
Cisco Systems VPN Client IPSec driver local kernel system pool corruption proof of concept exploit. Tested on CVPNDRVA.sys version 5.0.02.0090.
| | Author: | mu-b | | File Size: | 1909 | | Last Modified: | Jan 15 15:18:45 2008 |
| MD5 Checksum: | 9a950675a63993053f7e068a1d348056 |
|
| /// File Name: |
belong-bypass.txt |
Description:
|
It appears that Belong Site Builder version 0.1b allows for direct administrative access without credentials.
| | Author: | RoMaNcYxHaCkEr | | File Size: | 1908 | | Last Modified: | Jan 22 15:15:29 2008 |
| MD5 Checksum: | b95f01a3eb2a67e262e0351c9b0be7b8 |
|
| /// File Name: |
foojan-sql.txt |
Description:
|
Foojan WMS version 1.0 suffers from a remote SQL injection vulnerability in index.php.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 1868 | | Last Modified: | Jan 23 23:45:12 2008 |
| MD5 Checksum: | 2d57d991b185f2fec85795e1235eed6b |
|
| /// File Name: |
connectix-rfi.txt |
Description:
|
Connectix Boards versions 0.8.2 and below remote file inclusion exploit.
| | Author: | H-T Team | | Homepage: | http://no-hack.fr/ | | File Size: | 1854 | | Last Modified: | Jan 30 19:08:36 2008 |
| MD5 Checksum: | 02c5298d7c871be0ee474fca43e10674 |
|
| /// File Name: |
horde-disclose.txt |
Description:
|
Horde Web-Mail version 3.x suffers from a remote file disclosure vulnerability in go.php.
| | Author: | Eugene Minaev | | Homepage: | http://itdefence.ru/ | | File Size: | 1821 | | Last Modified: | Jan 6 19:56:06 2008 |
| MD5 Checksum: | 7f75a18c21013f2d00b95a6a05b8bfae |
|
| /// File Name: |
samphpweb-rfi.txt |
Description:
|
samPHPweb suffers from a remote file inclusion vulnerability in db.php.
| | Author: | Crackers_Child | | File Size: | 1819 | | Last Modified: | Jan 4 19:15:20 2008 |
| MD5 Checksum: | 9328247849d715787861662c2c374e53 |
|
| /// File Name: |
openbsd-deref.txt |
Description:
|
OpenBSD version 4.2 rtlabel_id2name() local null pointer dereference denial of service exploit.
| | Author: | Hunger | | File Size: | 1815 | | Last Modified: | Jan 18 19:49:20 2008 |
| MD5 Checksum: | 643db82bd27eeac5e151ce216b7264ff |
|
| /// File Name: |
phpresidence-sql.txt |
Description:
|
PHP-RESIDENCE version 0.7.2 suffers from a remote SQL injection vulnerability.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 1808 | | Last Modified: | Jan 17 00:06:45 2008 |
| MD5 Checksum: | e0672bef3352dcec3bfe83abbbe1b7ba |
|
| /// File Name: |
msrtc-insecure.txt |
Description:
|
Microsoft Rich Textbox Control version 6.0 (SP6) SaveFile() insecure method exploit.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 1807 | | Last Modified: | Jan 10 03:48:55 2008 |
| MD5 Checksum: | 20bf0322089d0d507d6aea6f9b908f49 |
|
| /// File Name: |
chilkatftp-insecure.txt |
Description:
|
Chilkat FTP ActiveX version 2.0 remote insecure method exploit that makes use of ChilkatCert.dll.
| | Author: | darkl0rd | | File Size: | 1802 | | Last Modified: | Jan 31 20:59:47 2008 |
| MD5 Checksum: | 3e5431ca32b15773d5f6284bf594ba6c |
|
| /// File Name: |
patchlink-pwn.txt |
Description:
|
The PatchLink Update Unix Client suffers from multiple file clobbering vulnerabilities allowing for privilege escalation.
| | Author: | Larry Cashdollar | | Homepage: | http://vapid.dhs.org | | File Size: | 1778 | | Last Modified: | Jan 25 19:16:55 2008 |
| MD5 Checksum: | accb2094f8acdb59cfd1d62387563748 |
|
| /// File Name: |
snitz-multi.txt |
Description:
|
Snitz Forums versions 3.4.06 and below suffer from direct database download and cross site scripting vulnerabilities.
| | Author: | DoZ | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1761 | | Last Modified: | Jan 7 14:20:54 2008 |
| MD5 Checksum: | 347539301ac0cfdcaeac8d49618e6276 |
|
| /// File Name: |
wpfgallery-sql.txt |
Description:
|
The Wordpress fGallery plugin version 2.4.1 suffers from a SQL injection vulnerability in firmrss.php.
| | Author: | H-T Team | | Homepage: | http://no-hack.fr/ | | File Size: | 1732 | | Last Modified: | Jan 28 13:01:40 2008 |
| MD5 Checksum: | 789b2a7b0aeeaafe3ab7e52daee8c74f |
|
| /// File Name: |
DSECRG-08-006.txt |
Description:
|
Nucleus CMS version 3.31 suffers from a cross site scripting vulnerability.
| | Author: | Sh2kerr,Stas Svistunovich | | Homepage: | http://www.dsec.ru/ | | File Size: | 1720 | | Last Modified: | Jan 29 21:54:53 2008 |
| MD5 Checksum: | f36ae354c56c03e88f058f9b282a125e |
|
| /// File Name: |
aflog-sqlxss.txt |
Description:
|
aflog version 1.01 suffers from cross site scripting and SQL injection vulnerabilities in comments.php.
| | Author: | shinmai | | File Size: | 1664 | | Last Modified: | Jan 23 23:15:00 2008 |
| MD5 Checksum: | c534e4b85bf8c741058d134b9d0b92d3 |
|
| /// File Name: |
loudblog-exec.txt |
Description:
|
LoudBlog versions 0.6.1 and below suffer from a remote code execution vulnerability.
| | Author: | Eugene Minaev | | Homepage: | http://itdefence.ru/ | | File Size: | 1660 | | Last Modified: | Jan 6 19:55:01 2008 |
| MD5 Checksum: | ce12a14bf27ce7ab789ea0c483aa55c4 |
|
| /// File Name: |
webportalcms-sql.txt |
Description:
|
WebPortal CMS versions 0.6.0 and below remote SQL injection exploit that makes use of index.php.
| | Author: | x0kster | | File Size: | 1642 | | Last Modified: | Jan 1 17:24:43 2008 |
| MD5 Checksum: | 6573085f890b5a3cd4e15792953f1f74 |
|
| /// File Name: |
DSECRG-08-002.txt |
Description:
|
aria version 0.99-6 suffers from a local file inclusion vulnerability in arias/help/effect.php.
| | Author: | Sh2kerr,Stas Svistunovich | | Homepage: | http://www.dsec.ru/ | | File Size: | 1639 | | Last Modified: | Jan 17 00:19:10 2008 |
| MD5 Checksum: | 4fb4c670f8e8b3609f7d951393ac6d1c |
|
| /// File Name: |
snetworks-rfi.txt |
Description:
|
SNetworks PHP Classifieds version 5.0 suffers from a remote file inclusion vulnerability.
| | Author: | Crackers_Child | | File Size: | 1625 | | Last Modified: | Jan 5 19:18:05 2008 |
| MD5 Checksum: | 85ff16ef11d3201a3b92320890de1778 |
|
| /// File Name: |
pacercms-sqlxss.txt |
Description:
|
PacerCMS version 0.6 suffers from cross site scripting and SQL injection vulnerabilities.
| | Author: | dB | | File Size: | 1619 | | Last Modified: | Jan 22 12:21:37 2008 |
| MD5 Checksum: | 1733c17a3f1f0a258ccb4c06db3cb594 |
|
|
|
|
|