what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 83 RSS Feed

Files Date: 2010-06-23 to 2010-06-24

How To Create An ASCII Shellcode
Posted Jun 23, 2010
Authored by Florian Gaultier

Whitepaper called How to Create an ASCII Shellcode.

tags | shellcode
SHA-256 | e324ab8a719a7f3c7be8dee8ff73a2e7d15dac6817490cd7aa8367f3abdcc9c8
Scholarship Award System SQL Injection
Posted Jun 23, 2010
Authored by L0rd CrusAd3r

Scholarship Award System suffers from denial of service and remote SQL injection vulnerabilities.

tags | exploit, remote, denial of service, vulnerability, sql injection
SHA-256 | b867b47d49ec9079304db4176a48c5df61eac61497c0142f57ad10bb84aa4ff0
Zero Day Initiative Advisory 10-112
Posted Jun 23, 2010
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 10-112 - This vulnerability allows remote attackers to upload arbitrary files on vulnerable installations of Novell Access Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PortalModuleInstallManager component of the Novell Management Console which exists within the servlet located within nps.jar. Due to a failure to sanitize '../' directory traversal modifiers from a parameter an attacker can specify any filename to upload arbitrary contents into. Successful exploitation can result in code execution under the context of the service.

tags | advisory, remote, arbitrary, code execution
advisories | CVE-2010-0284
SHA-256 | 2cb7c5bba9de39e113539364b91c22f85f014b081befb1c66f13a92f3430fab3
Zero Day Initiative Advisory 10-111
Posted Jun 23, 2010
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 10-111 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the connect method exposed via the ActionScript native object number 2200. If this function is called several times with differing strings, a memory corruption issue can be triggered. This can be exploited by remote attackers to execute arbitrary code under the context of the user running the web browser.

tags | advisory, remote, web, arbitrary
advisories | CVE-2010-2188
SHA-256 | 29b634a18ba5304ea43a70b6b27bbb1bf73bf16fed0ea42837e0c45c04b7da5b
Jeroen Guliker Site Pro SQL Injection
Posted Jun 23, 2010
Authored by JaMbA

Jeroen Guliker Site Pro suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 1333223373b3d349707515b518c2911d5d8142538127bf3b78d6946066b6649f
Mandriva Linux Security Advisory 2010-120
Posted Jun 23, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-120 - A vulnerability was reported in the SquirrelMail Mail Fetch plugin, wherein (when the plugin is activated by the administrator) a user is allowed to specify (without restriction) any port number for their external POP account settings. While the intention is to allow users to access POP3 servers using non-standard ports, this also allows malicious users to effectively port-scan any server through their SquirrelMail service (especially note that when a SquirrelMail server resides on a network behind a firewall, it may allow the user to explore the network topography (DNS scan) and services available (port scan) on the inside of (behind) that firewall. As this vulnerability is only exploitable post-authentication, and better more specific port scanning tools are freely available, we consider this vulnerability to be of very low severity. It has been fixed by restricting the allowable POP port numbers. The updated packages have been patched to correct this issue.

tags | advisory
systems | linux, mandriva
advisories | CVE-2010-1637
SHA-256 | c1ce6e51e0ff12140212416d19ef3ad63953447820df46e81f81e6daad09bd74
Baby Primo Site Pro SQL Injection
Posted Jun 23, 2010
Authored by JaMbA

Baby Primo Site Pro suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 0598d8cdb88ad24a85896029c314cbe63d653efb922b81fce5143a9a1c831548
Linker IMG 1.0 Remote File Inclusion
Posted Jun 23, 2010
Authored by Sniper Site Hacker

Linker IMG version 1.0 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 84e8f2a21c4bb29eeb1194037d1d1add83139c2e08808cfc364c549c04a2e251
myUPB 2.2.6 Local File Inclusion
Posted Jun 23, 2010
Authored by altbta

myUPB versions 2.2.6 and below suffer from backup related and local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, file inclusion
SHA-256 | 4fc0bd6b5ff6a7da33c3905788f5d628e6fe864f72b7b1f4bd94005c7d20923c
Suzuki SQL Injection
Posted Jun 23, 2010
Authored by Net.Edit0r

Suzuki suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 45e20def909d25e7c2e008a83ed3072276cce7784bb6edb2c35bfa830e731e83
[whem]-UPLoad 7.0 Insecure Cookie
Posted Jun 23, 2010
Authored by indoushka

[whem]-UPLoad version 7.0 suffers from an insecure cookie handling vulnerability.

tags | exploit, insecure cookie handling
SHA-256 | 0dfbaa34900640ff9b695ee269bcd5eb86802a80ce344d78485a92f282eebdae
Joomla Jomestate Remote File Inclusion
Posted Jun 23, 2010
Authored by Sid3 effects

The Joomla Jomestate component suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 7d5cd2a89085027552c250594c7020997fb3f10834b8fb3dc89cac37a9a890c5
Sysax Multi Server 5.25 Denial Of Service
Posted Jun 23, 2010
Authored by leinakesi

Sysax Multi Server version 5.25 suffers from denial of service vulnerabilities.

tags | exploit, denial of service, vulnerability
SHA-256 | 38e28b8ca34f7d09b76c40fd944821c5776f8cfafd638821d08b74cf4dd71b62
Gcms Generator SQL Injection
Posted Jun 23, 2010
Authored by Sid3 effects

Gcms Generator suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 841d8d128f448b5d3623276b19022c23c60951862a055ad3cbd8831864fe7dfe
Mandriva Linux Security Advisory 2010-121
Posted Jun 23, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-121 - Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database. Packages for 2008.0 and 2009.0 are provided as of the Extended https://store.mandriva.com/product_info.php?cPath=149&products_id=490 The updated packages have been patched to correct this issue.

tags | advisory, web, denial of service, php
systems | linux, mandriva
advisories | CVE-2010-0421
SHA-256 | f5e37817beaf60607a398d430cbcd45ddff318f0aa54fec0030969790a9fb0dc
Karkia SQL Injection
Posted Jun 23, 2010
Authored by Net.Edit0r

Karkia suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 15c0fdfb829c21b89904eda6a3358f4651cfdfbad6c9c9f98e2fb2aa288659f6
synType CMS Cross Site Scripting
Posted Jun 23, 2010
Authored by High-Tech Bridge SA | Site htbridge.com

synType CMS suffers from cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 9d6af60cbccc2772c551d103eba54bf7d0e52ff64c41fadd5d4938a4bab897a8
Boat Classifieds SQL Injection
Posted Jun 23, 2010
Authored by Sangteamtham

Boat Classifieds suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 70bc60822873a7bc35d7a2d5eaee8a4bc888c7ffa644fa285fce172947db311e
Joomla Community Cross Site Scripting
Posted Jun 23, 2010
Authored by Sid3 effects

The Joomla Community component suffers from a persistent cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 6806d0ab2b913f030a6ce42d072b4ccf05835ee9167727350f008074d2a189c5
Wing FTP 3.1.2 Denial Of Service
Posted Jun 23, 2010
Authored by Sumit Kumar Soni

Wing FTP version 3.1.2 suffers from a denial of service vulnerability.

tags | advisory, denial of service
SHA-256 | 716dbdce046552f06c005af0b689e2b30994f0ccfb799f41a279babe469c8964
Tab Napping Short Code
Posted Jun 23, 2010
Authored by Jbyte

Whitepaper called Tab Napping Short Code. Written in Spanish.

tags | paper
SHA-256 | 66ac51f7ae17d0dad779fe54ef29a672b407f89cb9d7e87e1ecfced627d733ca
Joomla JE Ajax SQL Injection
Posted Jun 23, 2010
Authored by L0rd CrusAd3r

The Joomla component JE Ajax event calendar suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | dfda533b6bfaf39e4cdf023f1acb1006b9b5a8368744ac31744820d4f648dbb5
Perl Pipe Exploitation Testing Tool
Posted Jun 23, 2010
Authored by Marshall Whittaker

This is a simple script that attempts to check if a CGI script suffers from an input validation command execution vulnerability.

tags | tool, cgi, scanner
systems | unix
SHA-256 | ee39234eb7bfde6be7b06a471b85c22615c756334e75f9853f44970c002c335b
Scribe CMS Cross Site Scripting
Posted Jun 23, 2010
Authored by High-Tech Bridge SA | Site htbridge.com

Scribe CMS suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | f806f60634a9c2e5d1a724155618fa9ae4ec19f37ebf62a4fa48eecb35ecba45
Rising Tide Media LLC CMS SQL Injection
Posted Jun 23, 2010
Authored by Cr3w-D, Dr.0rYX

Rising Tide Media LLC CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 651a4d6096c3f4f3956225bccfd18416fcfc95affe538f5a1b1d91c308d16773
Page 2 of 4
Back1234Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close