Section: .. / 0804-exploits /
| /// File Name: |
fifthave-sql.txt |
Description:
|
5th Avenue Shopping Cart suffers from a SQL injection vulnerability.
| | Author: | The-0utl4w | | Homepage: | http://aria-security.net/ | | File Size: | 592 | | Last Modified: | Apr 18 14:33:09 2008 |
| MD5 Checksum: | 98652c830b5eb269ba066d5b9beede65 |
|
| /// File Name: |
grape-rfi.txt |
Description:
|
Grape Statistics version 0.2a suffers from a remote file inclusion vulnerability.
| | Author: | MajnOoNxHaCkEr | | Homepage: | http://www.4rxh.com/ | | File Size: | 894 | | Last Modified: | Apr 18 14:21:58 2008 |
| MD5 Checksum: | b34b93b57d23f692fc30ba85e811c7e6 |
|
| /// File Name: |
divx66.py.txt |
Description:
|
DivX Player version 6.6.0 .SRT file handling SEH buffer overflow exploit.
| | Author: | Muts | | Homepage: | http://www.offensive-security.com/ | | File Size: | 8801 | | Last Modified: | Apr 18 14:20:31 2008 |
| MD5 Checksum: | d2684863a02bc465f44ff0eb972aecd9 |
|
| /// File Name: |
wikepage-xss.txt |
Description:
|
Wikepage Wiki version 2007-2 suffers from a cross site scripting vulnerability.
| | Author: | Attila Gerendi | | File Size: | 687 | | Last Modified: | Apr 18 14:18:16 2008 |
| MD5 Checksum: | 7049845824040de42e181b4fe65528b0 |
|
| /// File Name: |
lightnhard-multi.txt |
Description:
|
LightNEasy version 1.2.2 suffers from cross site scripting, directory traversal, and arbitrary file creation vulnerabilities.
| | Author: | Attila Gerendi | | File Size: | 1375 | | Last Modified: | Apr 18 14:17:42 2008 |
| MD5 Checksum: | 99a44b61dfac128a58014fe0de832e24 |
|
| /// File Name: |
intelcentrino-overflow.txt |
Description:
|
This Metasploit module exploits a stack overflow in the w22n51.sys driver provided with the Intel 2200BG integrated wireless adapter. This stack overflow allows remote code execution in kernel mode. The stack overflow is triggered when a 802.11 Probe response frame is received that contains multi vendor specific tag and "\x00" as essid and essid length element. This exploit was tested with version 8.0.12.20000 of the driver and an Intel Centrino 2200BG integrated wireless adapter.
| | Author: | Giuseppe Gottardi aka oveRet | | Homepage: | http://overet.securitydate.it | | File Size: | 5037 | | Last Modified: | Apr 17 18:22:22 2008 |
| MD5 Checksum: | 83410b8d8d0ea0068404d27d319a8c7f |
|
| /// File Name: |
xinelib-overflow.txt |
Description:
|
xine-lib versions 1.1.12 and below suffer from a stack-based buffer overflow vulnerability in the NES sound format demuxer (demux_nsf.c).
| | Author: | Guido Landi | | File Size: | 708 | | Last Modified: | Apr 17 13:40:07 2008 |
| MD5 Checksum: | 41575cac046f8a7bcba8c4586122dbc4 |
|
| /// File Name: |
e107chat-rfi.txt |
Description:
|
The E107 Chat module 123FlashChat version 6.8.0 suffers from a remote file inclusion vulnerability.
| | Author: | by_casper41 | | Homepage: | http://www.cyber-warrior.org/ | | File Size: | 742 | | Last Modified: | Apr 17 13:38:46 2008 |
| MD5 Checksum: | bdf84e8e44865a56c9e48d8361d99b15 |
|
| /// File Name: |
msworks-dos.txt |
Description:
|
Microsoft Works 7 crash proof of concept exploit that makes use of WkImgSrv.dll.
| | Author: | Shennan Wang | | Homepage: | http://hi.baidu.com/nansec | | File Size: | 487 | | Last Modified: | Apr 17 13:37:01 2008 |
| MD5 Checksum: | 957276c8810b72ebaa107f50e690cc6a |
|
| /// File Name: |
bsplayer-overflow.txt |
Description:
|
BS.Player version 2.27 Build 959 .SRT file buffer overflow exploit. denial of service exploit.
| | Author: | j0rgan | | Homepage: | http://www.jorgan.users.cg.yu/ | | File Size: | 515 | | Last Modified: | Apr 16 17:57:55 2008 |
| MD5 Checksum: | 198c713ca85cc6c329fd4374d39dfb07 |
|
| /// File Name: |
xplod-sql.txt |
Description:
|
XplodPHP AutoTutorials versions 2.1 and below suffer from a remote SQL injection vulnerability.
| | Author: | c02 | | Homepage: | http://www.dz-secure.com/ | | File Size: | 732 | | Last Modified: | Apr 16 17:42:50 2008 |
| MD5 Checksum: | 0e263d2dff0fae00315d50b52be54771 |
|
| /// File Name: |
lasernetcms-sql.txt |
Description:
|
Lasernet CMS version 1.5 suffers from a remote SQL injection vulnerability.
| | Author: | c02 | | Homepage: | http://www.dz-secure.com/ | | File Size: | 698 | | Last Modified: | Apr 15 22:24:19 2008 |
| MD5 Checksum: | ba34c8b6cc62515f8997cc28bcb03bd9 |
|
| /// File Name: |
divx-dos.txt |
Description:
|
DIVX Player versions 6.7.0 and below .SRT file buffer overflow proof of concept exploit.
| | Author: | securfrog | | File Size: | 956 | | Last Modified: | Apr 15 22:21:07 2008 |
| MD5 Checksum: | 8ed7830f55c4368453459ae33e0b037b |
|
| /// File Name: |
irforum-rfi.txt |
Description:
|
Istant-Replay Forums appear susceptible to a remote file inclusion vulnerability.
| | Author: | THuM4N | | File Size: | 902 | | Last Modified: | Apr 15 22:02:01 2008 |
| MD5 Checksum: | 8d64609c3c5d0858d0bccd3c4d99ba9f |
|
| /// File Name: |
w2b-rfi.txt |
Description:
|
W2B Online Banking appears susceptible to a remote file inclusion vulnerability.
| | Author: | THuM4N | | File Size: | 971 | | Last Modified: | Apr 15 22:01:12 2008 |
| MD5 Checksum: | 264484ee8624cc1653857406ec6572f1 |
|
| /// File Name: |
bosnews0206-direct.txt |
Description:
|
BosNews versions 2002-2006 appear to allow direct user addition without authentication.
| | Author: | H-T Team | | Homepage: | http://no-hack.fr/ | | File Size: | 714 | | Last Modified: | Apr 15 22:00:05 2008 |
| MD5 Checksum: | 568d81adb5c172eb9441eeb87719f5bb |
|
| /// File Name: |
bosnews40-direct.txt |
Description:
|
BosNews version 4.0 appears to allow direct user addition without authentication.
| | Author: | H-T Team | | Homepage: | http://no-hack.fr/ | | File Size: | 690 | | Last Modified: | Apr 15 21:59:30 2008 |
| MD5 Checksum: | 02bede2cf1b979f1adceacd9f853e739 |
|
| /// File Name: |
lightneasy-multi.txt |
Description:
|
LightNEasy SQLite / no database versions 1.2.2 and below suffer from code execution, SQL injection, file disclosure, and other vulnerabilities.
| | Author: | __GiReX__ | | Homepage: | http://girex.altervista.org/ | | File Size: | 3523 | | Last Modified: | Apr 15 21:52:54 2008 |
| MD5 Checksum: | 2e911597b2cae4852cf49dbb4cf6e0c6 |
|
| /// File Name: |
gallarific-xss.txt |
Description:
|
Gallarific appears susceptible to persistent cross site scripting vulnerabilities.
| | Author: | Thomas Pollet | | File Size: | 723 | | Last Modified: | Apr 15 21:50:42 2008 |
| MD5 Checksum: | 5018a6cf6981ad46114f4c9d8886cdac |
|
| /// File Name: |
antserver_exploit.py.txt |
Description:
|
BigAnt Server version 2.2 pre-auth remote SEH overflow exploit for Windows 2000 SP4 English that binds a shell to port 6080.
| | Author: | Matteo Memelli | | Homepage: | http://be4mind.com/ | | File Size: | 5930 | | Last Modified: | Apr 15 13:21:21 2008 |
| MD5 Checksum: | b9824c4e66cd826d328c6656e872640b |
|
|
|
|
|