exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 31 RSS Feed

Files Date: 2008-09-20

Debian Linux Security Advisory 1634-2
Posted Sep 20, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1634-2 - Rob Holland discovered several programming errors in WordNet, an electronic lexical database of the English language. These flaws could allow arbitrary code execution when used with untrusted input, for example when WordNet is in use as a back end for a web application. A regression was discovered in the original patch addressing this issue for WordNet, which this update fixes.

tags | advisory, web, arbitrary, code execution
systems | linux, debian
advisories | CVE-2008-2149
SHA-256 | 0b1a015d9c2dbf861498f679ae61a545d8164bf3135bf3645c81408026ffc049
Debian Linux Security Advisory 1642-1
Posted Sep 20, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1642-1 - Will Drewry discovered that the Horde, allows remote attackers to send an email with a crafted MIME attachment filename attribute to perform cross site scripting.

tags | advisory, remote, xss
systems | linux, debian
advisories | CVE-2008-3823
SHA-256 | 86fa3fafadc64c5326f69589f6e81f393290a5626436c792773c3cc89611f794
Debian Linux Security Advisory 1641-1
Posted Sep 20, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1641-1 - Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administrate MySQL databases over the web.

tags | advisory, remote, web, vulnerability
systems | linux, debian
advisories | CVE-2008-3197, CVE-2008-3456, CVE-2008-3457, CVE-2008-4096
SHA-256 | 6951024ce21cd3f9ffdd42b0fc285e8f843fcdeec6e27d7d33ee1110977642e6
Debian Linux Security Advisory 1640-1
Posted Sep 20, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1640-1 - Simon Willison discovered that in Django, a Python web framework, the feature to retain HTTP POST data during user reauthentication allowed a remote attacker to perform unauthorized modification of data through cross site request forgery. The is possible regardless of the Django plugin to prevent cross site request forgery being enabled.

tags | advisory, remote, web, python, csrf
systems | linux, debian
advisories | CVE-2008-3909, CVE-2007-5712
SHA-256 | 30351b8797d4bde99b857e633d429bdb41ac9026496fee8fe750b38e9e027d43
Mandriva Linux Security Advisory 2008-199
Posted Sep 20, 2008
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A number of vulnerabilities were discovered in Wireshark that could cause it to crash while processing malicious packets. This update provides Wireshark 1.0.3, which is not vulnerable to these issues.

tags | advisory, vulnerability
systems | linux, mandriva
advisories | CVE-2008-3146, CVE-2008-3932, CVE-2008-3933, CVE-2008-3934
SHA-256 | 47971e079bf45734339fd0f533d789363fc8928891232a1c4d30b4404e25506e
explay-xssxsrf.txt
Posted Sep 20, 2008
Authored by hodik

Explay CMS versions 2.1 and below suffer from persistent cross site scripting and cross site request forgery vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 26e1a5dc0c7920f5f2f226e65b518086844659c9a5d6cdfc0a96c4d5f0212dbf
myfwb-sql.txt
Posted Sep 20, 2008
Authored by Guns | Site 0x90.com.ar

MyFWB version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | bce220ad099560538daf2d2ac79ac49fdb4a6cc57f66b67a2b32ed2dd9c291b7
easylink-sql.txt
Posted Sep 20, 2008
Authored by Egypt Coder | Site sec-area.com

easyLink version 1.1.0 suffers from a remote SQL injection vulnerability in detail.php.

tags | exploit, remote, php, sql injection
SHA-256 | f10b35a00d5accdff38a63e3b3afb3a8c377e44d12eda0210d6e48442a0aa905
achievo-xss.txt
Posted Sep 20, 2008
Authored by Rohit Bansal

Achievo version 1.3.2-STABLE suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | a14c798136eb44fd0388628d2ad233df9724051fa5999d78092b15b404d25e7f
MU Security Advisory 2008-09.01
Posted Sep 20, 2008
Authored by MU Dynamics, Mu Security research team | Site labs.musecurity.com

An IKE_SA_INIT message with a Key Exchange payload containing a large number of NULL values can cause a crash of the IKEv2 charon daemon. The problem is strongSwan dereferences a NULL pointer returned by the mpz_export() function of the GNU Multiprecision Library (GMP). strongSwan versions 4.2.6 and below are affected.

tags | advisory
SHA-256 | a3597b49066b341935ee93779ea9ca112ab0a8104c7b1a8d4db0e4628d8bde6a
deslock-probe-read.c
Posted Sep 20, 2008
Authored by mu-b | Site digit-labs.org

DESlock+ versions 3.2.7 and below probe read local kernel denial of service exploit.

tags | exploit, denial of service, kernel, local
SHA-256 | 9b2d6d121d0e3ae16c49ee05aa2bdfabde347da1accaf8a8bacfa6fce5baafa2
deslock-probe-race.c
Posted Sep 20, 2008
Authored by mu-b | Site digit-labs.org

DESlock+ versions 3.2.7 and below local kernel race condition proof of concept denial of service exploit.

tags | exploit, denial of service, kernel, local, proof of concept
SHA-256 | 56b9e98449f73ed6597c17181fd6cf4b2214eeee2ca449e24187029fa75c03c6
deslock-overflow.c
Posted Sep 20, 2008
Authored by mu-b | Site digit-labs.org

DESlock+ versions 3.2.7 and below local kernel overflow proof of concept exploit.

tags | exploit, overflow, kernel, local, proof of concept
SHA-256 | 8beb788ab58e64d09723299b23349716f368a91d73ba5cd050071ef8073e8673
advancedelectron-exec.txt
Posted Sep 20, 2008
Authored by James Bercegay | Site gulftech.org

Advanced Electron Forum (AEF) versions 1.0.6 and below suffer from a remote code execution vulnerability.

tags | exploit, remote, code execution
SHA-256 | 6b7cad6edd71c0decb297e6dfa8f90c22132ac89bc5b7f3919c9f73a320b9989
drupal-hijack.txt
Posted Sep 20, 2008
Authored by Hanno Boeck | Site hboeck.de

Drupal CMS fails to set the secure flag in the session cookie allowing for session hijacking.

tags | advisory
advisories | CVE-2008-3661
SHA-256 | 6d5d4657228cd6039e3ccbfbac2cd8adc8cdb25a11f076f03f379e89ca0016db
arcadempro-sql.txt
Posted Sep 20, 2008
Authored by Hussin X | Site tryag.cc

Arcadem Pro suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | cf6b9be7b638894a9d6be877c864c82a1a83b01b059d802d2beff216ca3991ae
Gentoo Linux Security Advisory 200809-9
Posted Sep 20, 2008
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200809-09 - A memory leak in Postfix might allow local users to cause a Denial of Service. It has been discovered than Postfix leaks an epoll file descriptor when executing external commands, e.g. user-controlled $HOME/.forward or $HOME/.procmailrc files. NOTE: This vulnerability only concerns Postfix instances running on Linux 2.6 kernels. Versions less than 2.4.9 are affected.

tags | advisory, denial of service, kernel, local, memory leak
systems | linux, gentoo
advisories | CVE-2008-3889
SHA-256 | 9c8335b7774c98cfeaed558a9d598717ed37fac34ab4a3fb906fe1da12090605
eng-4.23-public.rar
Posted Sep 20, 2008
Authored by Nelson Brito

ENG, or Encore Next Generation, is a false-negative morphic tool that can bypass IDS/IPS via the randomization of return addresses, random writable addresses, junk code injection, and more.

tags | tool, intrusion detection
systems | unix
SHA-256 | 98147acc62fc6afb8a017830278e2f8800d2ded4cc07b1e6e2a203b3c93a17d2
Secunia Security Advisory 31830
Posted Sep 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - t0fx has reported two vulnerabilities in H-Sphere, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, vulnerability, xss
SHA-256 | 3445e5adf95b92bfaa0c72781a8c7a37f2c4fba6e7339d6858f5a25595f5407c
Secunia Security Advisory 31880
Posted Sep 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Some security issues have been reported in emacspeak, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

tags | advisory, local
SHA-256 | b4df1814657e7be5a1e3abba1954a6c0976ef20a7bc0e5ca48b387c1be43a86e
Secunia Security Advisory 31887
Posted Sep 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A security issue has been reported in the Cluster Project, which can be exploited by malicious, local users to perform certain actions with escalated privileges.

tags | advisory, local
SHA-256 | 4f4786ab099f54a327f07d29f4e9a540468b22e836f980ebc997d6ce91596c3b
Secunia Security Advisory 31897
Posted Sep 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in the Secure Directory (kw_secdir) extension for TYPO3, which can be exploited by malicious users to compromise a vulnerable system.

tags | advisory
SHA-256 | 895bd70a2d31b15c6e1ce46ada5b05e6ec87574a100451c69ecfa325354091b5
Secunia Security Advisory 31911
Posted Sep 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Xerox ESS/Network Controller, which can be exploited by malicious people to compromise a vulnerable system.

tags | advisory
SHA-256 | 48a1f691294e2f252159a410e2d05a873b3df37a4826c2155d18dae98e3b02ff
Secunia Security Advisory 31919
Posted Sep 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

tags | advisory, denial of service, local
systems | solaris
SHA-256 | ecb748fa2ce51a5055c40c8f1a601af4f2c89d09671100b737d472210f4fa038
Secunia Security Advisory 31924
Posted Sep 20, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in ISC BIND, which can be exploited by malicious people to cause a DoS (Denial of Service).

tags | advisory, denial of service
SHA-256 | caa0f967228228303c79bffa3c030056003724d20445ba40d88b896371c62fb5
Page 1 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close