Section: .. / 0801-exploits /
| /// File Name: |
mybb1210-exec.txt |
Description:
|
MyBulletinBoard aka MyBB versions 1.2.10 and below remote code execution exploit.
| | Author: | Silentz | | Homepage: | http://www.w4ck1ng.com/ | | File Size: | 3456 | | Last Modified: | Jan 17 00:07:32 2008 |
| MD5 Checksum: | 8c673277aa03238877b18dcc1717fac4 |
|
| /// File Name: |
axigen-format.c |
Description:
|
AXIGEN version 5.0.x AXIMilter format string exploit that binds a shell to port 4141.
| | Author: | hempel | | File Size: | 3436 | | Last Modified: | Jan 21 20:51:13 2008 |
| MD5 Checksum: | c2c1760cfad111e6e0b5723e03c58e3a |
|
| /// File Name: |
tribisur-sql.txt |
Description:
|
Tribisur versions 2.0 and below remote SQL injection exploit.
| | Author: | x0kster | | File Size: | 3380 | | Last Modified: | Jan 5 19:16:27 2008 |
| MD5 Checksum: | df59b93e8049773067947eeeb242405f |
|
| /// File Name: |
eticket-multi.txt |
Description:
|
eTicket version 1.5.5.2 suffers from SQL injection, cross site scripting, and cross site request forgery vulnerabilities.
| | Author: | L4teral | | File Size: | 3335 | | Last Modified: | Jan 7 14:16:54 2008 |
| MD5 Checksum: | 9901795955dc3d263b9505c186d3a22c |
|
| /// File Name: |
richstrong-sql.txt |
Description:
|
RichStrong CMS remote SQL injection exploit that makes use of showproduct.asp.
| | Author: | JosS | | Homepage: | http://www.spanish-hackers.com/ | | File Size: | 3266 | | Last Modified: | Jan 15 15:21:34 2008 |
| MD5 Checksum: | 6242307d6f420fc255d27402adea1d19 |
|
| /// File Name: |
move-overwrite.txt |
Description:
|
Move Networks Quantum Streaming player SEH overwrite exploit that spawns calc.exe.
| | Author: | Elazar Broad | | File Size: | 3119 | | Related CVE(s): | CVE-2007-4722 | | Last Modified: | Jan 9 01:41:32 2008 |
| MD5 Checksum: | 97e369f1acd1cf342ca475a18cbb3655 |
|
| /// File Name: |
coolplayer217-overflow.txt |
Description:
|
CoolPlayer version 2.17 .m3u playlist stack overflow exploit that binds a shell to port 4444.
| | Author: | Trancek | | Related File: | coolplayer-overflow.txt | | File Size: | 3028 | | Last Modified: | Jan 5 19:14:41 2008 |
| MD5 Checksum: | a0506f18c97386e7552ffa9405628953 |
|
| /// File Name: |
joomla1013-csrf.txt |
Description:
|
Joomla! versions 1.0.13 and below suffer form cross site request forgery vulnerabilities. Exploit included that will force an administrator to add a user upon a simple page view.
| | Author: | J. Carlos Nieto | | File Size: | 2933 | | Last Modified: | Jan 8 15:39:12 2008 |
| MD5 Checksum: | e1a7b37ae32dacb651466b3e5aac7ec3 |
|
| /// File Name: |
mas-rfi.txt |
Description:
|
Member Area System (MAS) suffers from a remote file inclusion vulnerability in view_func.php.
| | Author: | ShipNX | | File Size: | 2898 | | Last Modified: | Jan 11 13:39:58 2008 |
| MD5 Checksum: | 2ea1f1114b4921535979b4e70729649e |
|
| /// File Name: |
spambam.pl.txt |
Description:
|
Exploit that demonstrates that the WordPress SpamBam plugin can be bypassed due to relying on the client for security.
| | Author: | Jose Palazon | | File Size: | 2870 | | Last Modified: | Jan 12 19:33:16 2008 |
| MD5 Checksum: | a050be5d360bce73b4e8bacb9fc11906 |
|
| /// File Name: |
joomlachrono-rfi.txt |
Description:
|
The Joomla ChronoForms component version 2.3.5 suffers from remote file inclusion vulnerabilities.
| | Author: | Crackers_Child | | File Size: | 2790 | | Last Modified: | Jan 30 19:18:29 2008 |
| MD5 Checksum: | 6e12f70d767dee0f9dfdaeec3e98741d |
|
| /// File Name: |
binn-sql.txt |
Description:
|
Binn SBuilder suffers from a remote blind SQL injection vulnerability.
| | Author: | JosS | | Homepage: | http://www.spanish-hackers.com/ | | File Size: | 2785 | | Last Modified: | Jan 14 14:04:51 2008 |
| MD5 Checksum: | 3b1f0ee0373c08968f1b1d6f0aa20e9c |
|
| /// File Name: |
flexnet-overwrite.txt |
Description:
|
Macrovision FlexNet Connect download manager is susceptible to an arbitrary file download/overwrite vulnerability.
| | Author: | Elazar Broad | | File Size: | 2690 | | Last Modified: | Jan 14 17:35:29 2008 |
| MD5 Checksum: | cd3597bf1d417eee3e6df8ec35c24189 |
|
| /// File Name: |
f5-xss.txt |
Description:
|
The F5 BIG-IP web management interface is susceptible to a cross site scripting vulnerability via the search functionality. Tested against version 9.4.3.
| | Author: | nnposter | | File Size: | 2669 | | Last Modified: | Jan 14 17:37:05 2008 |
| MD5 Checksum: | 2c83b193605b1fc8b97dd6bff5a1a5f9 |
|
| /// File Name: |
oracle-xdboverflow.txt |
Description:
|
Oracle 10g R1 xdb.xdb_pitrig_pkg.pitrig_truncate buffer overflow proof of concept exploit.
| | Author: | Sh2kerr | | Homepage: | http://www.dsec.ru/ | | File Size: | 2635 | | Last Modified: | Jan 28 12:24:40 2008 |
| MD5 Checksum: | 777f96805c33108f566d3d08d6a96268 |
|
| /// File Name: |
nuvico-heap.txt |
Description:
|
NUVICO DVR NVDV4 / PdvrAtl module with PdvrAtl.DLL version 1.0.1.25 remote heap overflow exploit for Internet Explorer 7 on Windows XP SP2.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 2436 | | Last Modified: | Jan 14 14:30:00 2008 |
| MD5 Checksum: | 72b01f1ef6de7519689522b9fb5ea7e2 |
|
| /// File Name: |
mindmeld-rfi.txt |
Description:
|
Mindmeld version 1.2.0.10 suffers from multiple remote file inclusion vulnerabilities.
| | Author: | David Wharton | | File Size: | 2421 | | Last Modified: | Jan 31 23:31:14 2008 |
| MD5 Checksum: | fecd943192817f59b2f81250445610c3 |
|
| /// File Name: |
simple32-xss.txt |
Description:
|
Simple Forum version 3.2 suffers from file disclosure and cross site scripting vulnerabilities.
| | Author: | tomplixsee | | File Size: | 2397 | | Last Modified: | Jan 28 12:58:53 2008 |
| MD5 Checksum: | 2a1bfd12e5011303c544d2532d02d391 |
|
| /// File Name: |
bannerss-xsrfxss.txt |
Description:
|
Banner Student version 7.3 suffers from cross site request forgery and cross site scripting vulnerabilities.
| | Author: | Brendan M. Hickey | | Homepage: | http://www.bhickey.net/ | | File Size: | 2377 | | Last Modified: | Jan 29 21:51:17 2008 |
| MD5 Checksum: | 82815fecb3a6885d9c5d0930c2b08875 |
|
| /// File Name: |
oracle-truncatesql.txt |
Description:
|
Oracle 10g R1 xdb.xdb_pitrig_pkg.pitrig_truncate SQL injection exploit that grabs password hashes.
| | Author: | Sh2kerr | | Homepage: | http://www.dsec.ru/ | | File Size: | 2338 | | Last Modified: | Jan 28 12:27:28 2008 |
| MD5 Checksum: | 4a412e9d0e2d8fe9a3efff112abeda14 |
|
|
|
|
|