Section: .. / 0707-exploits /
| /// File Name: |
linpha131-sql.txt |
Description:
|
LinPHA versions 1.3.1 and below remote blind SQL injection exploit that makes use of new_images.php.
| | Author: | EgiX | | File Size: | 6506 | | Last Modified: | Jul 31 00:15:12 2007 |
| MD5 Checksum: | d3838baf9474200047b3e0e616b2e435 |
|
| /// File Name: |
php123-sql.txt |
Description:
|
PHP123 Top Sites suffers from a SQL injection vulnerability in category.php.
| | Author: | t0pp8uzz, xprog | | File Size: | 1135 | | Last Modified: | Jul 31 00:14:03 2007 |
| MD5 Checksum: | 058aa636729cc459d0dd6c474d4ac8fa |
|
| /// File Name: |
simpleblog-sql.txt |
Description:
|
SimpleBlog version 3.0 remote SQL injection exploit that makes use of comments_get.asp.
| | Author: | TrinTiTTY, MurderSkillz | | Homepage: | http://www.g00ns.net/ | | File Size: | 2250 | | Last Modified: | Jul 31 00:12:58 2007 |
| MD5 Checksum: | 212158da48ea0f607cef159a4a68631f |
|
| /// File Name: |
berthanas-sql.txt |
Description:
|
Berthanas Ziyaretci Defteri version 2.0 suffers from a SQL injection vulnerability.
| | Author: | Yollubunlar | | Homepage: | http://yollubunlar.org/ | | File Size: | 653 | | Last Modified: | Jul 31 00:07:55 2007 |
| MD5 Checksum: | a5f2042e475fde8a09c3594eb87aab70 |
|
| /// File Name: |
suskunduygular-sql.txt |
Description:
|
SuskunDuygular - Yelik Sistemi version 0.1 suffers from a SQL injection vulnerability.
| | Author: | Yollubunlar | | Homepage: | http://yollubunlar.org/ | | File Size: | 771 | | Last Modified: | Jul 31 00:07:12 2007 |
| MD5 Checksum: | ad1598af550350fb74214b6e72fe7aa1 |
|
| /// File Name: |
friendscript-rfi.txt |
Description:
|
Friend Script versions 2.4 and 2.5 suffer from a remote file inclusion vulnerability.
| | Author: | Yollubunlar | | Homepage: | http://yollubunlar.org/ | | File Size: | 959 | | Last Modified: | Jul 31 00:05:40 2007 |
| MD5 Checksum: | 8e795e6cb9c4f32b5a5e6ec02963aaf4 |
|
| /// File Name: |
metyus-sql.txt |
Description:
|
Metyus Forum Portal version 1.0 suffers from a SQL injection vulnerability in philboard_forum.asp.
| | Author: | Cr@zy_King | | File Size: | 826 | | Last Modified: | Jul 27 22:27:46 2007 |
| MD5 Checksum: | 0337192b1865016797aa31b5cd2473b6 |
|
| /// File Name: |
sblog073-xss.txt |
Description:
|
sBlog version 0.7.3 Beta suffers from cross site scripting vulnerabilities.
| | Author: | Guns | | Homepage: | http://www.0x90.com.ar/ | | File Size: | 226 | | Last Modified: | Jul 27 22:16:07 2007 |
| MD5 Checksum: | 172796cc28794d1cf009c8dbf5e67ad6 |
|
| /// File Name: |
nukeditXSS.txt |
Description:
|
Nukedit is susceptible to a cross site scripting vulnerability in Login.ASP.
| | Author: | d3hydr8 | | File Size: | 1159 | | Last Modified: | Jul 27 21:35:22 2007 |
| MD5 Checksum: | 18bf926247d338e28ea316623f368174 |
|
| /// File Name: |
m3ks-adv-24.7.07.txt |
Description:
|
PhpHostBot suffers from a remote file inclusion vulnerability in login_form.
| | Author: | S4M3K | | Homepage: | http://www.m3ks.org/ | | File Size: | 1043 | | Last Modified: | Jul 27 21:32:14 2007 |
| MD5 Checksum: | 30abc3c86e83e38cf35bb6b6ca459810 |
|
| /// File Name: |
dependet-sql.txt |
Description:
|
Dependet Forums suffers from a SQL injection vulnerability.
| | Homepage: | http://aria-security.net/ | | File Size: | 376 | | Last Modified: | Jul 27 21:30:53 2007 |
| MD5 Checksum: | bd52b5525c3b4196ec4df359da476ca3 |
|
| /// File Name: |
argo-exec.txt |
Description:
|
m1srvx.dll version 1.8.9.1 ArGoSoft mail server arbitrary data write and remote code execution exploit.
| | Author: | callAX | | Homepage: | http://goodfellas.shellcode.com.ar/ | | File Size: | 4578 | | Last Modified: | Jul 27 21:23:32 2007 |
| MD5 Checksum: | f549fe232b8efe69551a8e58808431a4 |
|
| /// File Name: |
aix53-ftp.txt |
Description:
|
IBM AIX versions 5.3 sp6 and below ftp gets() local root exploit.
| | Author: | qaaz | | File Size: | 3447 | | Last Modified: | Jul 27 21:19:57 2007 |
| MD5 Checksum: | fe602c478e3e43a6fa609caf13e687d7 |
|
| /// File Name: |
aix53-pioout.txt |
Description:
|
IBM AIX versions 5.3 sp6 and below pioout arbitrary library loading local root exploit.
| | Author: | qaaz | | File Size: | 635 | | Last Modified: | Jul 27 21:18:35 2007 |
| MD5 Checksum: | d6d2294e4a1335c917a21268a3b1c59a |
|
| /// File Name: |
aix53-capture.txt |
Description:
|
IBM AIX versions 5.3 sp6 and below capture Terminal Sequence local root exploit.
| | Author: | qaaz | | File Size: | 3832 | | Last Modified: | Jul 27 21:17:21 2007 |
| MD5 Checksum: | bc7b85cb47e06a823f693d7d932a215e |
|
| /// File Name: |
seditio-upload.txt |
Description:
|
Seditio CMS versions 121 and below suffer from a remote file upload vulnerability in pfs.php.
| | Author: | A.D.T | | Homepage: | http://err0rgroup.org/ | | File Size: | 660 | | Last Modified: | Jul 27 21:15:29 2007 |
| MD5 Checksum: | ea69856e7ae5bad09ad34fbc9a6a8aa2 |
|
| /// File Name: |
phpgd2-overflow.txt |
Description:
|
PHP php_gd2.dll imagepsloadfont local buffer overflow proof of concept exploit.
| | Author: | r0ut3r | | File Size: | 1382 | | Last Modified: | Jul 27 21:13:53 2007 |
| MD5 Checksum: | 221f1f2ff4c914f572516952a31d73ec |
|
| /// File Name: |
phpsysinfo-xss.txt |
Description:
|
PHPSysInfo version 2.5.4 suffers from a cross site scripting vulnerability in index.php.
| | Author: | Doz | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1145 | | Last Modified: | Jul 27 21:12:02 2007 |
| MD5 Checksum: | b2486fce50328bf6d43d9d629511e10d |
|
| /// File Name: |
lsa_transnames_heap-solaris.rb.txt |
Description:
|
This Metasploit module triggers a heap overflow in the LSA RPC service of the Samba daemon. This module uses the TALLOC chunk overwrite method (credit Ramon and Adriano), which only works with Samba versions 3.0.21 through 3.0.24. Additionally, this module will not work when the Samba "log level" parameter is higher than "2". Solaris version.
| | Author: | Ramon de Carvalho Valle, Adriano Lima, H D Moore | | Homepage: | http://www.risesecurity.org/ | | File Size: | 5515 | | Related CVE(s): | CVE-2007-2446 | | Last Modified: | Jul 26 02:04:19 2007 |
| MD5 Checksum: | 9f07c9cd8fd013c9608f103024c1c839 |
|
| /// File Name: |
lsa_transnames_heap-linux.rb.txt |
Description:
|
This Metasploit module triggers a heap overflow in the LSA RPC service of the Samba daemon. This module uses the TALLOC chunk overwrite method (credit Ramon and Adriano), which only works with Samba versions 3.0.21 through 3.0.24. Additionally, this module will not work when the Samba "log level" parameter is higher than "2". Linux version.
| | Author: | Ramon de Carvalho Valle, Adriano Lima, H D Moore | | Homepage: | http://www.risesecurity.org/ | | File Size: | 8017 | | Related CVE(s): | CVE-2007-2446 | | Last Modified: | Jul 26 02:00:21 2007 |
| MD5 Checksum: | 4f3d9021ab7aeab8ee51f9ee5605ad0c |
|
| /// File Name: |
mozillaprotocolabuse.zip |
Description:
|
The Mozilla application platform currently has an unpatched input validation flaw which allows you to specify arbitrary command line arguments to any registered URL protocol handler process. Thunderbird version 2.0.0.5 fixes this. Full exploits included.
| | Author: | Thor Larholm | | Homepage: | http://larholm.com/ | | File Size: | 49162 | | Last Modified: | Jul 26 01:23:47 2007 |
| MD5 Checksum: | 1eb5ac7bc33d9647cfbf1967c41b6c50 |
|
| /// File Name: |
clever-overwrite.txt |
Description:
|
Clever Internet ActiveX Suite version 6.2 arbitrary file download/overwrite exploit that makes use of CLINETSUITEX6.OCX.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 1444 | | Last Modified: | Jul 26 01:05:14 2007 |
| MD5 Checksum: | 311f7af75451bf02dfbe1c959d421aca |
|
| /// File Name: |
ipswitch-overflow.txt |
Description:
|
IPSwitch IMail server 2006 SEARCH remote stack overflow exploit. Binds a shell to port 1154.
| | Author: | ZhenHan.Liu | | Homepage: | http://www.ph4nt0m.org/ | | File Size: | 5764 | | Last Modified: | Jul 26 01:04:01 2007 |
| MD5 Checksum: | 5aec044f25a17b719729eb54cd242c04 |
|
|
|
|
|