Section: .. / 0702-exploits /
| /// File Name: |
oracle-sql.txt |
Description:
|
Oracle 9i/10g DBMS_EXPORT_EXTENSION SQL injection exploit.
| | Author: | bunker | | Homepage: | http://rawlab.mindcreations.com/ | | File Size: | 3078 | | Last Modified: | Feb 6 06:53:15 2007 |
| MD5 Checksum: | e8c1ad7a358b928402e6586d17beed9f |
|
| /// File Name: |
r3-stealer-1.0.pl.txt |
Description:
|
SAP Web AS version 6.40 enserver.exe file downloader exploit.
| | Author: | Nicob | | Related File: | sapwebas-dos.txt | | File Size: | 2950 | | Last Modified: | Feb 13 06:42:42 2007 |
| MD5 Checksum: | 5752598c931045ff201480846280017d |
|
| /// File Name: |
syscp1215-exec.txt |
Description:
|
The System Control Panel (SysCP) suffers from a flaw that allows an attack the ability to inject and execute any code as root. Versions 1.2.15 and below are affected. Details provided.
| | Author: | Florian Lippert | | Homepage: | http://www.syscp.org/ | | File Size: | 2731 | | Last Modified: | Feb 8 06:40:20 2007 |
| MD5 Checksum: | e36e3775b0f9c1536e9b110da418c334 |
|
| /// File Name: |
webspell-sql.txt |
Description:
|
webSPELL versions 4.01.02 and below remote SQL injection exploit.
| | Author: | DNX | | File Size: | 2681 | | Last Modified: | Feb 24 03:08:29 2007 |
| MD5 Checksum: | bcddf1aff042870376c7304c49320c81 |
|
| /// File Name: |
magicnews-rfixss.txt |
Description:
|
Magic News version 1.0.2 suffers from cross site scripting and remote file inclusion vulnerabilities.
| | Author: | HACKERS PAL | | Homepage: | http://www.soqor.net/ | | File Size: | 2560 | | Last Modified: | Feb 24 02:43:12 2007 |
| MD5 Checksum: | af88c1a99fa103b999a8dc8820f56eb6 |
|
| /// File Name: |
adv64-y3dips-2007.txt |
Description:
|
Open-CMS Site Protection Plugin suffers from a remote file inclusion flaw.
| | Author: | y3dips | | Homepage: | http://echo.or.id/ | | File Size: | 2515 | | Last Modified: | Feb 13 07:38:07 2007 |
| MD5 Checksum: | ce492393cbbc9fcfd2e17deba0c99f6a |
|
| /// File Name: |
ip3netaccess.txt |
Description:
|
IP3 NetAccess versions below 4.1.9.6 suffer from a classic directory traversal flaw allowing for arbitrary file disclosure.
| | Author: | Sebastian Wolfgarten | | File Size: | 2512 | | Last Modified: | Feb 13 07:43:14 2007 |
| MD5 Checksum: | a7b9e3a200228856ffd3c4290438ded8 |
|
| /// File Name: |
NGS-traversal.txt |
Description:
|
Oracle 10g R2 Enterprise Manager suffers from a classic directory traversal flaw. Details provided.
| | Author: | Mark Litchfield | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 2489 | | Last Modified: | Feb 1 05:49:30 2007 |
| MD5 Checksum: | 0c5b1958a382b2b56a78fd3ccad8e0f0 |
|
| /// File Name: |
cotv2-dos.txt |
Description:
|
cotv 2.0 suffers from a client-side denial of service vulnerability due to a lack of validation. Demonstration exploit included.
| | Author: | poplix | | File Size: | 2325 | | Last Modified: | Feb 6 05:20:16 2007 |
| MD5 Checksum: | 09fcabf3a5299f63313c1f1e27df059b |
|
| /// File Name: |
spydir.c |
Description:
|
Exploit that demonstrates the vulnerability in ReadDirectoryChangesW() for Microsoft Windows 2000/XP/2003/Vista.
| | Author: | 3APA3A | | Homepage: | http://securityvulns.com/ | | Related File: | readirchange.txt | | File Size: | 2281 | | Related CVE(s): | CVE-2007-0843 | | Last Modified: | Feb 24 03:47:11 2007 |
| MD5 Checksum: | f7f6bf6fe0ea633cd5976b0a644ad70c |
|
| /// File Name: |
openssh-timing.txt |
Description:
|
Portable OpenSSH versions 3.6.1p-PAM / 4.1-SUSE and below timing attack exploit.
| | Author: | Marco Ivaldi | | File Size: | 2277 | | Last Modified: | Feb 14 23:23:28 2007 |
| MD5 Checksum: | 293040e79450f8a12b90cd78eb7f3bc6 |
|
| /// File Name: |
atmail-xss.txt |
Description:
|
@Mail suffers from cross site scripting flaws in search.pl.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 2227 | | Last Modified: | Feb 14 21:10:30 2007 |
| MD5 Checksum: | d60b8c17ec10bebc6c28f497e00b60bb |
|
| /// File Name: |
coppermine-blindsql.txt |
Description:
|
Coppermine Photo Gallery version 1.3.x blind SQL injection exploit.
| | Author: | s0cratex | | File Size: | 2204 | | Last Modified: | Feb 28 01:45:24 2007 |
| MD5 Checksum: | a455d05a88b89a11ba6a2296c29cffb3 |
|
| /// File Name: |
ovidentia5x-rfi.txt |
Description:
|
Ovidentia version 5.x remote file inclusion exploit.
| | Author: | Hotturk | | File Size: | 2077 | | Last Modified: | Feb 13 07:06:58 2007 |
| MD5 Checksum: | 5994fe7e672751b845e5bac5dfb3b932 |
|
| /// File Name: |
uphotogallery-xss.txt |
Description:
|
Uphotogallery version 1.1 is susceptible to cross site scripting attacks.
| | Author: | Doz | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1903 | | Last Modified: | Feb 6 06:27:37 2007 |
| MD5 Checksum: | 25b2d4fb2ceb3bdd1a1217cd8a5eb8e2 |
|
| /// File Name: |
SA-20070226-0.txt |
Description:
|
SEC Consult Security Advisory 20070226-0 - The 3rd party module Pagesetter for PostNuke is susceptible to a local file inclusion vulnerability. Versions 6.2.0 and 6.3.0 beta 5 are affected.
| | Author: | D. Matscheko | | Homepage: | http://www.sec-consult.com | | File Size: | 1896 | | Last Modified: | Mar 6 01:51:48 2007 |
| MD5 Checksum: | 80f3f17ffa2c97e576a6821c1866f9a8 |
|
|
|
|
|