what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 43 of 43 RSS Feed

Files Date: 2007-03-14 to 2007-03-15

iframeicash.txt
Posted Mar 14, 2007
Authored by Thierry Zoller | Site secdev.zoller.lu

The Iframe-Cash/Iframe-Dollars Adware company does not only rootkit your machine, it also keystroke logs your banking details. Lovely.

tags | advisory
SHA-256 | b1813e4a381860177beb2d4841d451719bde3e5627d9a8789ebccc36b67d6ec0
Debian Linux Security Advisory 1265-1
Posted Mar 14, 2007
Authored by Debian | Site debian.org

Debian Security Advisory 1265-1 - Several security related problems have been discovered in Mozilla and derived products. Several vulnerabilities in the layout engine allow remote attackers to cause a denial of service and possibly permit them to execute arbitrary code. Several vulnerabilities in the JavaScript engine allow remote attackers to cause a denial of service and possibly permit them to execute arbitrary code. A bug in the js_dtoa function allows remote attackers to cause a denial of service. "shutdown" discovered a vulnerability that allows remote attackers to gain privileges and install malicious code via the watch JavaScript function. Steven Michaud discovered a programming bug that allows remote attackers to cause a denial of service. "moz_bug_r_a4" reported that the src attribute of an IMG element could be used to inject JavaScript code. Georgi Guninski discovered several heap-based buffer overflows that allow remote attackers to execute arbitrary code.

tags | advisory, remote, denial of service, overflow, arbitrary, javascript, vulnerability
systems | linux, debian
advisories | CVE-2006-6497, CVE-2006-6498, CVE-2006-6499, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6505
SHA-256 | 30c49707966199037decb53c0e4941c6faae1ea6a5cdc8e8e657d83ce41e3144
Gentoo Linux Security Advisory 200703-10
Posted Mar 14, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200703-10 - The KHTML code allows for the execution of JavaScript code located inside the Title HTML element, a related issue to the Safari error found by Jose Avila. Versions less than 3.5.5-r8 are affected.

tags | advisory, javascript
systems | linux, gentoo
advisories | CVE-2007-0478, CVE-2007-0537
SHA-256 | bcced2e9620602f6184ded8df9419abb96205767c97f5c62bad6a71665af370a
phpmysport-rfi.txt
Posted Mar 14, 2007
Authored by vitux

phpMySport CMS suffers from a remote file inclusion vulnerability in menu.php.

tags | exploit, remote, php, code execution, file inclusion
SHA-256 | b6f8cde9f621ac52ba954b1f1c75e49d30c597e47e9d446a9ffebaf71c61ad1a
arpalert-2.0.5.tar.gz
Posted Mar 14, 2007
Authored by Thierry Fournier | Site perso.numericable.fr

arpalert uses ARP address monitoring to help prevent unauthorized connections on the local network. If an illegal connection is detected, a program or script is launched, which could be used to send an alert message, for example.

Changes: Multiple bug fixes and a bit of code clean up.
tags | local
systems | unix
SHA-256 | 2c25fa7a934d2c234a3b9e18f674d9c90386f8b4a51e18867b52a909a2d080f9
seccheck-0.7.1.tar.gz
Posted Mar 14, 2007
Authored by Zazzy Bob | Site zazzybob.com

Seccheck is a feature rich, modular, host-level security checker for Solaris 10. Easily expandable with customized modules, Seccheck produces highly detailed reports based around known and published security best-practices and guidelines. It also produces recommendations on how to fix flagged security issues.

systems | unix, solaris
SHA-256 | 49bd82e46dc8c74f9f065a49e3d0c9a44f47e519c355a3bae7cb7b92903d018f
fslint-2.20.tar.gz
Posted Mar 14, 2007
Authored by pixelbeat | Site pixelbeat.org

FSlint is a toolkit to find various forms of lint on a filesystem. At the moment it reports duplicate files, bad symbolic links, troublesome file names, empty directories, non stripped executables, temporary files, duplicate/conflicting (binary) names, and unused ext2 directory blocks.

Changes: Updated Danish translation. Various packaging changes and improvements.
tags | tool
systems | unix
SHA-256 | 51be9a10ba885cebc39b24673c96d594944e7b7d3a0f2d1f7ed632b67e1a7d44
NukeSentinel-sql.txt
Posted Mar 14, 2007
Authored by DarkFig | Site acid-root.new.fr

NukeSentinel versions 2.5.06 and below SQL injection exploit for use with mysql versions 4.0.24 and above.

tags | exploit, sql injection
SHA-256 | e3cc24343fd420723a8e26cf924ee898a7a68f6a9c355fcab4fc34d0fe741846
adv68-K-159-2007.txt
Posted Mar 14, 2007
Authored by M.Hasran Addahroni | Site advisories.echo.or.id

PMB Services versions 3.0.13 and below suffer from multiple remote file inclusion vulnerabilities. Full details provided.

tags | exploit, remote, vulnerability, file inclusion
SHA-256 | 560dfa19b6b3d8cbf442115fc20031612e63a1f3839c3539368832c53d468be1
grayscale-multi.txt
Posted Mar 14, 2007
Authored by Omnipresent

Grayscale Blog version 0.8.0 suffers from SQL injection, security bypass, and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, sql injection
SHA-256 | 645903ad556da0bc3a0748ca86238ce02c8e413ec53b4ddbd76691e38a5cdfce
duyuru-sql.txt
Posted Mar 14, 2007
Authored by Cr@zy_King

Duyuru Scripti remote blind SQL injection exploit.

tags | exploit, remote, sql injection
SHA-256 | 70cfd9d85a621f64d1832165848bc6bbb369922b87ecba6be653e62d67ef3eba
softnews-rfi.txt
Posted Mar 14, 2007
Authored by Hasadya Raed

A remote file inclusion vulnerability exists in SoftNews Media Group.

tags | exploit, remote, code execution, file inclusion
SHA-256 | d8dcf06027c79ca34af18de454fd37480a62f59b2cb981bed97a787dcfc7185a
SubDog-rfi.txt
Posted Mar 14, 2007
Authored by Hasadya Raed

A remote file inclusion vulnerability exists in Script Premod SubDog 2.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 2af460772dfd357814dc91de4aee6b002e9594d3fcba1f6a3dde47a99ba8a551
phpnuke80-cookie.txt
Posted Mar 14, 2007
Authored by Aleksandar aka sale83

PHP Nuke versions 8.0 and below suffer from a cookie manipulation flaw that allows for SQL injection and local file inclusion attacks.

tags | exploit, local, php, sql injection, file inclusion
SHA-256 | 748af9b7537384380eb74b9c56382ba8700522a7ca6b519d851246e3c2e4e1e4
10MinSecAudit.zip
Posted Mar 14, 2007
Authored by Cesar Cerrudo

Whitepaper that demonstrates an extremely simple technique to quickly audit a software product in order to infer how trustable and secure it is. Oracle is used as a test case. Proof of concept exploit is included.

tags | paper, proof of concept
SHA-256 | 904c6850febb646527b3645a17ff83d6aba25216e7fbcf87791119aa245eb915
Gentoo Linux Security Advisory 200703-9
Posted Mar 14, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200703-09 - Kees Cook of the Ubuntu Security Team has identified multiple vulnerabilities in Smb4K. Versions less than 0.6.10a are affected.

tags | advisory, vulnerability
systems | linux, gentoo, ubuntu
advisories | CVE-2007-0472, CVE-2007-0473, CVE-2007-0474, CVE-2007-0475
SHA-256 | ad8219aa0975deb02ceb57584cdc4d147ca7e9f12aa836b8a5e2b034d2e20afe
Gentoo Linux Security Advisory 200703-8
Posted Mar 14, 2007
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200703-08 - Tom Ferris reported a heap-based buffer overflow involving wide SVG stroke widths that affects SeaMonkey. Various researchers reported some errors in the JavaScript engine potentially leading to memory corruption. SeaMonkey also contains minor vulnerabilities involving cache collision and unsafe pop-up restrictions, filtering or CSS rendering under certain conditions. All those vulnerabilities are the same as in GLSA 200703-04 affecting Mozilla Firefox. Versions less than 1.1.1 are affected.

tags | advisory, overflow, javascript, vulnerability
systems | linux, gentoo
advisories | CVE-2006-6077, CVE-2007-0775, CVE-2007-0776, CVE-2007-0777, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0801, CVE-2007-0981, CVE-2007-0995
SHA-256 | ecaa1e726a2e8cdce8273041013ccaa3441879102769280f1c9c9ff93d0ec1d9
wp2-xss.txt
Posted Mar 14, 2007
Authored by g30rg3_x

The WordPress 2.0.x and 2.1.x releases suffer from a cross site scripting vulnerability in wp_title().

tags | advisory, xss
SHA-256 | e6eea503e42de5b1bf7d615840d958c79982cffeaae090fc1bc65934cc958f9b
Page 2 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close