Section: .. / 0601-exploits /
| /// File Name: |
EV0006.txt |
Description:
|
phpBook versions 1.3.2 and below suffer from a php code execution flaw due to an unsanitized variable. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 909 | | Last Modified: | Jan 4 05:39:06 2006 |
| MD5 Checksum: | b122a4b3240ffbe2b36aae734f74775c |
|
| /// File Name: |
EV0005.txt |
Description:
|
PHPenpals version 310704 suffers from a SQL injection flaw in profile.php. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1036 | | Last Modified: | Jan 4 05:38:16 2006 |
| MD5 Checksum: | 6f79885444231de57267c05ea2925576 |
|
| /// File Name: |
EV0004.txt |
Description:
|
Chipmunk Guestbook versions 1.4 and below suffer from a cross site scripting flaw. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1079 | | Last Modified: | Jan 4 05:37:03 2006 |
| MD5 Checksum: | 428b07a8f3feee943c2022a41e2dc2f8 |
|
| /// File Name: |
EV0003.txt |
Description:
|
oaBoard version 1.0 suffers from a remote php include and execution flaw. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 912 | | Last Modified: | Jan 4 05:36:06 2006 |
| MD5 Checksum: | f04ea6970108e626932bebd68e851346 |
|
| /// File Name: |
EV0002.txt |
Description:
|
VEGO Links Builder version 2.0 suffers from a SQL injection flaw. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 972 | | Last Modified: | Jan 4 05:35:04 2006 |
| MD5 Checksum: | f49b036b4313d32d340ecf3120295932 |
|
| /// File Name: |
EV0001.txt |
Description:
|
VEGO Web Forum versions 1.26 and below suffer from SQL injection flaws. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1541 | | Last Modified: | Jan 4 05:34:04 2006 |
| MD5 Checksum: | 0ac527c4e0ac44134a4a7114cd55dc14 |
|
| /// File Name: |
cijfer-cnxpl.pl.txt |
Description:
|
CuteNews versions 1.4.1 and below remote command execution exploit.
| | Author: | cijfer | | File Size: | 4283 | | Last Modified: | Jan 3 04:00:19 2006 |
| MD5 Checksum: | 9cbbd77a8e6c1ac666176d216b180652 |
|
| /// File Name: |
drupal.txt |
Description:
|
Drupal is susceptible to cross site scripting attacks via IMG tags.
| | Author: | Liz0ziM | | Homepage: | http://www.biyo.tk | | File Size: | 1922 | | Last Modified: | Jan 3 03:46:39 2006 |
| MD5 Checksum: | 435c1a197381b2c0f151a3a79bf6cda4 |
|
| /// File Name: |
xfocus-SD-060101.txt |
Description:
|
getCommand and getShell under AIX 5.3 still suffer from multiple exposure flaws.
| | Homepage: | http://www.xfocus.org | | File Size: | 1337 | | Last Modified: | Jan 3 03:44:22 2006 |
| MD5 Checksum: | 07a1b07775be3bad6d588df88ef20ec4 |
|
| /// File Name: |
mtink.c |
Description:
|
/usr/bin/mtink local root exploit which overflows the HOME environment variable. For all versions of linux, especially Debian and Gentoo.
| | Author: | Icesk | | File Size: | 867 | | Last Modified: | Jan 1 16:03:38 2006 |
| MD5 Checksum: | a51dc4863862f6bf39008443953c0d5d |
|
| /// File Name: |
PaQFile_Share.txt |
Description:
|
eFileGo v3.01 contains multiple vulnerabilities including remote command execution, file upload, denial of service, and a directory traversal issue in upload.exe. The vulnerable eFileGo web server runs on TCP port 608.
| | Author: | dr_insane | | File Size: | 3069 | | Last Modified: | Jan 1 15:37:04 2006 |
| MD5 Checksum: | 26f8b9da7a9fec8026bda1b0fff8c34c |
|
|
|
|
|