exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 69 RSS Feed

Files Date: 2010-09-08 to 2010-09-09

Ubuntu Security Notice 983-1
Posted Sep 8, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 983-1 - Markus Wuethrich discovered that sudo did not always verify the user when a group was specified in the Runas_Spec. A local attacker could exploit this to execute arbitrary code as root if sudo was configured to allow the attacker to use a program as a group when the attacker was not a part of that group.

tags | advisory, arbitrary, local, root
systems | linux, ubuntu
advisories | CVE-2010-2956
SHA-256 | 62d38ec064d0f0ae54ffdd39f4c5cebe6d080d478403d1d548b88dc150afceba
Zenphoto 1.3 SQL Injection / Cross Site Scripting
Posted Sep 8, 2010
Authored by Bogdan Calin | Site acunetix.com

Zenphoto version 1.3 suffers from remote SQL injection and cross site scripting vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 9aba0f3c57e1571d92188f285c1e29dcc64f3a7c82c836c543a3f9fb95eb3db7
OpenJournalSystem Stored Cross Site Scripting
Posted Sep 8, 2010
Authored by Sweet

OpenJournalSystem suffers from stored cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
SHA-256 | 2f321b47ef923d1b39d04a32346be20f9aac9c34c1079bd7860cba711e6a7de4
FCMS 2.3 SQL Injection
Posted Sep 8, 2010
Authored by Sweet

FCMS version 2.3 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | daf4160b7e75b7748e74d46da1039263d2bcab8032f63b4ca70cecf7ae169d34
EnanoCMS 1.1.7pl1 Blind SQL Injection
Posted Sep 8, 2010
Authored by Sweet

EnanoCMS version 1.1.7pl1 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 91ac1532fe38504b6d8acadec6628503e0f25e90f03b20cf87ccf3a29ef65ea7
LuckySploit Exploit Pack PHP Code Execution
Posted Sep 8, 2010
Authored by Laurent Oudot | Site tehtri-security.com

LuckySploit Exploit Pack suffers from a remote php code execution vulnerability.

tags | exploit, remote, php, code execution
SHA-256 | e0ca493b860d23d3c7a4efa33ec94327d45fef4b6ce9c3046f0b621288bf4469
Google Chrome Arbitrary Extensions Detection
Posted Sep 8, 2010
Authored by Lostmon | Site lostmon.blogspot.com

Google Chrome suffers from an installed extensions arbitrary detection vulnerability.

tags | exploit, arbitrary
SHA-256 | 52da5016877181aca474a508679782a3b2ff97357ecd8b355f349ada96f2d008
ColdUserGroup 1.06 Blind SQL Injection
Posted Sep 8, 2010
Authored by mr_me

ColdUserGroup version 1.06 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 4d561fc606364ff9f9c632eea881ffa65e13486e9b56f015c12fe0dba863cda0
ColdOfficeView 2.04 Blind SQL Injection
Posted Sep 8, 2010
Authored by mr_me

ColdOfficeView version 2.04 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 855d1817a0ca53d21dc578095619d1437c8e8a51f5917ba373073c5ecdbe79b6
Micronetsoft RV Dealer SQL Injection
Posted Sep 8, 2010
Authored by L0rd CrusAd3r

Micronetsoft RV Dealer Website suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 14a649ccdcec269d6ff99d9a59e36913289a26c004e0531222d9147fed3eff0c
Gentoo Linux Security Advisory 201009-3
Posted Sep 8, 2010
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201009-3 - The secure path feature and group handling in sudo allow local attackers to escalate privileges. Versions less than 1.7.4_p3-r1 are affected.

tags | advisory, local
systems | linux, gentoo
advisories | CVE-2010-1646, CVE-2010-2956
SHA-256 | 64d26ed806b78f1b66f52278ea929c7c037d7db811b81866bdff928a6b17c6fb
Month Of Abysssec Undisclosed Bugs - Novell Netware
Posted Sep 8, 2010
Authored by Abysssec, Shahin | Site abysssec.com

Month Of Abysssec Undisclosed Bugs - Novell Netware NWFTPD suffers from a RMD/RNFR/DELE argument parsing buffer overflow.

tags | advisory, overflow
SHA-256 | c81669f9a0dab88339bc13b0f5395505b6284452be79e0f17e5cb416a3709456
Month Of Abysssec Undisclosed Bugs - Novell Netware
Posted Sep 8, 2010
Authored by Abysssec, Shahin | Site abysssec.com

Month Of Abysssec Undisclosed Bugs - Novell Netware NWFTPD suffers from a RMD/RNFR/DELE argument parsing buffer overflow.

tags | exploit, overflow
SHA-256 | a54ce7c53b97508938cdfba5be3024fb391acc0b3ad3f07b240c9903e0fab1b9
BeehiveForum 0.9.1 Cross Site Request Forgery / Cross Site Scripting
Posted Sep 8, 2010
Authored by Sweet

BeehiveForum version 0.9.1 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
SHA-256 | 312402be459d7c166149f3fb0f18c3c24fa774b85e63d1ebe82957d5d8227fb1
ITSecTeam Shell 1.1
Posted Sep 8, 2010
Authored by ItSecTeam

This is a backdoor PHP shell from ITSecTeam.

tags | tool, shell, php, rootkit
systems | unix
SHA-256 | 428640bd9e6ab10814a7560818cb822084078acd863ae3339c157e9a31c524db
Horde Application Framework 3.3.8 Cross Site Scripting
Posted Sep 8, 2010
Authored by Moritz Naumann

Horde Application Framework versions 3.3.8 and below suffer from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 01e9ddbfdbf4d32de19869d646b2a9456bddb547a09999086f5546c532116c2d
NetReconn Scanning Tool Collection 1.78
Posted Sep 8, 2010
Authored by Jay Fink

Netreconn is a collection of network scan/recon tools that are relatively small compared to their larger cousins. These include nstrobe, ipdump, and ndecode.

Changes: Tools have been collapsed into one front end. Runs faster than previous versions. Experimental passive and ipv6 active scanning has been added.
tags | tool
systems | unix
SHA-256 | 92622b34ac44670925923291aeac935a6275c7479f227a13aafc70595c01c109
Gentoo Linux Security Advisory 201009-2
Posted Sep 8, 2010
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201009-2 - Insecure permission handling in maildrop might allow local attackers to elevate their privileges. Christoph Anton Mitterer reported that maildrop does not properly drop its privileges when run as root. Versions less than 2.4.2 are affected.

tags | advisory, local, root
systems | linux, gentoo
advisories | CVE-2010-0301
SHA-256 | 2bfb6f35985ffdffe7307c2836a10362f23cfba6a7ac26e966bdc15cc16b8a84
Debian Linux Security Advisory 2104-1
Posted Sep 8, 2010
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2104-1 - Several remote vulnerabilities have been discovered in the BGP implementation of Quagga, a routing daemon.

tags | advisory, remote, vulnerability
systems | linux, debian
advisories | CVE-2010-2948, CVE-2010-2949
SHA-256 | 8646a8caace9c92b61e4ac01d05fc51d46e9086df3cd81a4e5ef9950e0139977
Joomla Aardvertiser 2.1 Blind SQL Injection
Posted Sep 8, 2010
Authored by Stephan Sattler

The Joomla Aardvertiser component version 2.1 suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 8efaa33898ed5fe60a2313b37c9b026a3d3536914f277339d98e0c3d4cb4cd2e
MySource Matrix 3.28.3 Cross Site Scripting
Posted Sep 8, 2010
Authored by LiquidWorm | Site zeroscience.mk

MySource Matrix version 3.28.3 suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 0b4022da0c3745024cfcbc130e3a207b832debd2b1888d8ca111d89d5a5154bf
Mandriva Linux Security Advisory 2010-171
Posted Sep 8, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-171 - The cluster logical volume manager daemon in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted control commands. The updated packages have been patched to correct this issue.

tags | advisory, denial of service, local
systems | linux, redhat, mandriva
advisories | CVE-2010-2526
SHA-256 | c4273b3d2b834ca292d7a33635b5ab63841e94dd24978262fa809e54e9c0fca8
Adobe Acrobat Reader Memory Corruption
Posted Sep 8, 2010
Authored by ItSecTeam

Adobe Acrobat Reader suffers from an acroform_PlugInMain memory corruption vulnerability.

tags | exploit
SHA-256 | 13643ed28eba98678a6df11405f3ca7ea0cc124d66bef70d224e26ab0e031857
Micronetsoft Rental Property Management Website SQL Injection
Posted Sep 8, 2010
Authored by L0rd CrusAd3r

Micronetsoft Rental Property Management Script suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 95591f99d865571a4921815ff2a2639621f9b410eb7a5006c94fb9445ddd775a
Month Of Abysssec Undisclosed Bugs - DynPage 1.0
Posted Sep 8, 2010
Authored by Abysssec | Site abysssec.com

Month Of Abysssec Undisclosed Bugs - DynPage versions 1.0 and below suffer from local file disclosure and administrative hash disclosure vulnerabilities.

tags | exploit, local, vulnerability
SHA-256 | 264706b93351a6424f348269befb08a69d0d5091243f96ae114ef3833a49f6d5
Page 2 of 3
Back123Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close