Section: .. / 0601-exploits /
| /// File Name: |
geronimo_css.txt |
Description:
|
Apache Geronimo version 1.0 suffers from cross site scripting vulnerabilities.
| | Author: | Oliver Karow | | Homepage: | http://www.oliverkarow.de | | File Size: | 1361 | | Last Modified: | Jan 21 21:41:13 2006 |
| MD5 Checksum: | 246d64556b8377602e7647db2718be1c |
|
| /// File Name: |
ua367XSS.txt |
Description:
|
Ultimate Auction versions 3.67 and below suffer from cross site scripting flaws.
| | Author: | Querkopf | | File Size: | 613 | | Last Modified: | Jan 21 21:37:52 2006 |
| MD5 Checksum: | c6ca4a78777cbf9d2ea5dfb5d43f4fd1 |
|
| /// File Name: |
EZDatabase.txt |
Description:
|
EZDatabase versions below 2.1.2 are susceptible to cross site scripting, directory traversal, and path disclosure flaws.
| | Author: | Josh Zlatin-Amishav | | File Size: | 906 | | Last Modified: | Jan 21 20:06:58 2006 |
| MD5 Checksum: | e1fb3cf01a1dcfc6a357961936e7690f |
|
| /// File Name: |
MSIEDoS.txt |
Description:
|
Microsoft(R) Internet Explorer 5 and 6 suffer from a remote denial of service flaw using IMG and XML elements. Proof of concept code included.
| | Author: | Inge Henriksen | | Homepage: | http://ingehenriksen.blogspot.com/ | | File Size: | 1441 | | Last Modified: | Jan 21 20:03:48 2006 |
| MD5 Checksum: | 624ee3829bec9e7afa29fcf02a6044ea |
|
| /// File Name: |
simpleBlogXSS.txt |
Description:
|
SimpleBlog version 2.1 suffers from SQL injection and cross site scripting flaws.
| | Author: | Zinho | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 943 | | Last Modified: | Jan 21 20:00:16 2006 |
| MD5 Checksum: | d40972d7a6f05a6c0503f9a771e7f9b7 |
|
| /// File Name: |
ISAA-2006-001.txt |
Description:
|
123flashchat server versions 5.1 and below suffer from directory traversal attacks that allow for arbitrary file creation.
| | Author: | Jesus Olmos Gonzalez | | File Size: | 4698 | | Last Modified: | Jan 21 19:58:32 2006 |
| MD5 Checksum: | 6b899581652a6d00c78163f8d0a75085 |
|
| /// File Name: |
ddsnSQL.txt |
Description:
|
DDSN is susceptible to SQL injection attacks via the login sequence.
| | Author: | khc | | File Size: | 739 | | Last Modified: | Jan 21 08:17:12 2006 |
| MD5 Checksum: | f20b868cba46e9332a90e1c8e440d970 |
|
| /// File Name: |
dcpXSS.txt |
Description:
|
DCP Portal is susceptible to cross site scripting.
| | Author: | Night_Warrior | | File Size: | 302 | | Last Modified: | Jan 21 08:16:24 2006 |
| MD5 Checksum: | 3c522eddab2a4bc31ba3e47ac879d5c1 |
|
| /// File Name: |
alstrasoftXSS.txt |
Description:
|
AlstraSoft Template Seller Pro is susceptible to cross site scripting attacks.
| | Author: | Night_Warrior | | File Size: | 291 | | Last Modified: | Jan 21 07:19:33 2006 |
| MD5 Checksum: | 09bbcbb65ca8895a4a794ae450dc91ad |
|
| /// File Name: |
EV0029.txt |
Description:
|
Light Weight Calendar version 1.0 is susceptible to remote php code execution. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1071 | | Last Modified: | Jan 21 07:18:17 2006 |
| MD5 Checksum: | 3953cd22bff9935a5f9a96a0d6bc6969 |
|
| /// File Name: |
simpleBlog21.txt |
Description:
|
SimpleBlog version 2.1 is susceptible to SQL injection and cross site scripting attacks due to a lack of variable sanitization.
| | Author: | Zinho | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1213 | | Last Modified: | Jan 15 18:27:07 2006 |
| MD5 Checksum: | 40c9f202077dfc69e005da9b100dd50e |
|
| /// File Name: |
homeftp_v1.1_xpl.c |
Description:
|
HomeFTP versions 1.1 and below remote denial of service exploit.
| | Author: | Pi3cH, cvh | | Homepage: | http://www.kapda.ir/ | | File Size: | 3339 | | Last Modified: | Jan 15 18:21:14 2006 |
| MD5 Checksum: | 928270b4d741a17745a9f45166872e89 |
|
| /// File Name: |
ezDatabase20.txt |
Description:
|
ezDatabase versions 2.0 and below are susceptible to remote php file inclusion flaws due to a lack of sanitizing variables.
| | Author: | Pridels Team | | Homepage: | http://pridels.blogspot.com | | File Size: | 1047 | | Last Modified: | Jan 15 18:19:30 2006 |
| MD5 Checksum: | b063abadc38f3993016c8b7fed112f70 |
|
| /// File Name: |
DSR-farmerswife44sp1.pl.txt |
Description:
|
Farmers WIFE version 4.4 sp1 ftpd remote exploit that allows for system compromise.
| | Author: | kokanin | | File Size: | 2957 | | Last Modified: | Jan 15 18:14:43 2006 |
| MD5 Checksum: | 8f952e01a07259244b3b2baf44fe55e3 |
|
| /// File Name: |
xmame.c |
Description:
|
xmame version 0.102 -lang local buffer overflow exploit.
| | Author: | Qnix | | Related File: | Xmamebo.txt | | File Size: | 2381 | | Last Modified: | Jan 15 18:09:07 2006 |
| MD5 Checksum: | bdd219342e85d52090960f09a93a0678 |
|
| /// File Name: |
MiniNukeSQL-2.txt |
Description:
|
MiniNuke CMS System versions 1.8.2 and below suffer from a flaw where an authenticated user can change any password via membership.asp.
| | Author: | nukedx | | Homepage: | http://www.nukedx.com | | File Size: | 1515 | | Last Modified: | Jan 15 18:01:33 2006 |
| MD5 Checksum: | 0b9270f90b1f336310b682775ceb9e28 |
|
| /// File Name: |
MiniNukeSQL.txt |
Description:
|
MiniNuke CMS System versions 1.8.2 and below suffer from a SQL injection attack in news.asp.
| | Author: | nukedx | | Homepage: | http://www.nukedx.com | | File Size: | 1014 | | Last Modified: | Jan 15 17:59:57 2006 |
| MD5 Checksum: | 68d24208b9496fa63148b8e47e2ce704 |
|
| /// File Name: |
DMA-2006-0112a.txt |
Description:
|
Using ussp-push from the Toshiba Bluetooth Stack versions 4.00.23(T) and below, an attacker can place a trojaned file anywhere on the filesystem.
| | Author: | Kevin Finisterre | | Homepage: | http://www.digitalmunition.com/ | | File Size: | 3620 | | Last Modified: | Jan 15 17:54:17 2006 |
| MD5 Checksum: | 13c47dbcf05a5bc3f1fedca80adbb8b8 |
|
| /// File Name: |
EV0028.txt |
Description:
|
Wordcircle 2.17 is susceptible to SQL injection and cross site scripting flaws. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 974 | | Last Modified: | Jan 15 17:36:38 2006 |
| MD5 Checksum: | 3341e56cb78277d002f0d92594b54f6d |
|
| /// File Name: |
EV0027.txt |
Description:
|
Wordcircle version 2.17 is susceptible to SQL injection attacks that allows for authentication bypass. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 989 | | Last Modified: | Jan 15 17:35:41 2006 |
| MD5 Checksum: | 142aa49c577d9d8aa7f1872cd3e41d41 |
|
| /// File Name: |
EV0026.txt |
Description:
|
TankLogger version 2.4 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1048 | | Last Modified: | Jan 15 17:34:48 2006 |
| MD5 Checksum: | 1a254764515ad09d8c965a402d714a6d |
|
| /// File Name: |
HelmXSS.txt |
Description:
|
Helm version 3.2.8 is susceptible to cross site scripting attacks.
| | Author: | M.Neset KABAKLI | | Homepage: | http://www.wakiza.com | | File Size: | 925 | | Last Modified: | Jan 15 17:33:08 2006 |
| MD5 Checksum: | cfe94c7d04512524524ed95512c5ff82 |
|
|
|
|
|