Section: .. / 0702-exploits /
| /// File Name: |
xlatunes-sql.txt |
Description:
|
XLAtunes version 0.1 suffers from a remote SQL injection vulnerability.
| | Author: | 0x90 | | File Size: | 267 | | Last Modified: | Feb 23 03:54:12 2007 |
| MD5 Checksum: | bb4255de0be613cd2b22764ed0120bd9 |
|
| /// File Name: |
phpnuke-sql.txt |
Description:
|
PHP-Nuke Module Emporium versions 2.3.0 and below remote SQL injection exploit.
| | Author: | ajann | | File Size: | 9228 | | Last Modified: | Feb 20 02:17:55 2007 |
| MD5 Checksum: | 353a24f571bea2a91359187d2ae7deae |
|
| /// File Name: |
revenge_proftpd_ctrls_26.pl.txt |
Description:
|
ProFTPD versions 1.3.0 and 1.3.0a controls local root exploit that binds a shell to tcp/31337. This one works for the 2.6 kernel series.
| | Author: | revenge | | Homepage: | http://www.0xcafebabe.it/ | | File Size: | 3686 | | Last Modified: | Feb 20 02:09:30 2007 |
| MD5 Checksum: | 545a3a957304f724c6ce23e6ff75f481 |
|
| /// File Name: |
axiagen.c |
Description:
|
Axigen eMail Server version 2.0 Beta format string exploit that binds a shell to port 31337. Not tested.
| | Author: | fugich | | File Size: | 6119 | | Last Modified: | Feb 17 05:55:06 2007 |
| MD5 Checksum: | ec6405482e949071196784b15d5168ae |
|
| /// File Name: |
maildisable-v6.pl.txt |
Description:
|
Mail Enable Professional versions 2.35 and below remote exploit. Binds a shell to port 1337.
| | Author: | mu-b | | File Size: | 4299 | | Last Modified: | Feb 17 05:50:00 2007 |
| MD5 Checksum: | 5526079197ebd97d09e0b9f5c2a02765 |
|
| /// File Name: |
maildisable-v3.pl.txt |
Description:
|
Mail Enable Professional/Enterprise version 2.32 through 2.34 remote exploit. Binds a shell to port 1337.
| | Author: | mu-b | | File Size: | 4605 | | Last Modified: | Feb 17 05:49:05 2007 |
| MD5 Checksum: | 8a4f5b347c116e89a4361458183df659 |
|
| /// File Name: |
ezboo-bad.txt |
Description:
|
Ezboo webstats allows direct download access to sensitive files.
| | Author: | sn0oPy | | File Size: | 490 | | Last Modified: | Feb 17 05:45:19 2007 |
| MD5 Checksum: | 05d117d6b2280c57a5b1f8bd96a7200c |
|
| /// File Name: |
demtrac-log.txt |
Description:
|
Dem_trac allows direct download access to the system's log file without authentication.
| | Author: | sn0oPy | | File Size: | 457 | | Last Modified: | Feb 17 05:44:32 2007 |
| MD5 Checksum: | 0100d8835d01c2eafa42d293244d19e2 |
|
| /// File Name: |
cedstat131-xss.txt |
Description:
|
CedStat version 1.31 suffers from a cross site scripting flaw.
| | Author: | sn0oPy | | File Size: | 423 | | Last Modified: | Feb 16 09:07:25 2007 |
| MD5 Checksum: | 72035b6f9493e72a8b4a5d3ae3f0aee2 |
|
| /// File Name: |
deskpro-xss.txt |
Description:
|
Deskpro version 1.1.0 suffers from a cross site scripting flaw.
| | Author: | BLacK ZeRo | | File Size: | 371 | | Last Modified: | Feb 16 08:19:10 2007 |
| MD5 Checksum: | 255202d92a54ed746f9a50e440add431 |
|
| /// File Name: |
calexp-xss.txt |
Description:
|
Calendar Express 2 suffers from a cross site scripting flaw.
| | Author: | BLacK ZeRo | | File Size: | 449 | | Last Modified: | Feb 16 08:18:31 2007 |
| MD5 Checksum: | f92eb4f2a73ffcc159d8f4158729b173 |
|
| /// File Name: |
lotus.sh.txt |
Description:
|
Lotus Domino versions R6 and below Webmail remote password hash dumper exploit.
| | Author: | Marco Ivaldi | | File Size: | 3578 | | Last Modified: | Feb 14 23:24:54 2007 |
| MD5 Checksum: | 2d50a561beba95bd4cb07456f3325e8d |
|
| /// File Name: |
openssh-timing.txt |
Description:
|
Portable OpenSSH versions 3.6.1p-PAM / 4.1-SUSE and below timing attack exploit.
| | Author: | Marco Ivaldi | | File Size: | 2277 | | Last Modified: | Feb 14 23:23:28 2007 |
| MD5 Checksum: | 293040e79450f8a12b90cd78eb7f3bc6 |
|
| /// File Name: |
12070214.txt |
Description:
|
Jupiter CMS version 1.1.5 suffers from multiple vulnerabilities including SQL injection, cross site scripting, local and remote file inclusion, and more. I think it should be a do-over.
| | Author: | DarkFig | | Homepage: | http://www.acid-root.new.fr/ | | File Size: | 8609 | | Last Modified: | Feb 14 23:17:00 2007 |
| MD5 Checksum: | e99bcc28b629a60c407dba283724c814 |
|
| /// File Name: |
maildisable-v7.pl.txt |
Description:
|
MailEnable Pro/Enterprise version 2.37 proof of concept exploit that makes use of an out of bounds memory read in the NTLM authentication routines.
| | Author: | mu-b | | File Size: | 1610 | | Last Modified: | Feb 14 22:22:27 2007 |
| MD5 Checksum: | 29f826ef0ba28ec861252188df4484ac |
|
| /// File Name: |
maildisable-v5.pl.txt |
Description:
|
MailEnable Pro/Enterprise versions below 2.351 proof of concept exploit that makes use of an out of bounds memory read in the NTLM authentication routines.
| | Author: | mu-b | | File Size: | 1816 | | Last Modified: | Feb 14 22:21:28 2007 |
| MD5 Checksum: | 40cb4c0dc389db110f093feaf9d26a17 |
|
| /// File Name: |
fullasprite-sqlxss.txt |
Description:
|
Fullasprite Shop suffers from cross site scripting and SQL injection vulnerabilities.
| | Author: | ShaFuck31 | | File Size: | 349 | | Last Modified: | Feb 14 21:21:00 2007 |
| MD5 Checksum: | 0c26d0e2a25162248dec5f5a197dc4dc |
|
| /// File Name: |
atmail-xss.txt |
Description:
|
@Mail suffers from cross site scripting flaws in search.pl.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 2227 | | Last Modified: | Feb 14 21:10:30 2007 |
| MD5 Checksum: | d60b8c17ec10bebc6c28f497e00b60bb |
|
| /// File Name: |
inertia-rfi.txt |
Description:
|
Inertia News version 0.02 beta suffers from a remote file inclusion flaw.
| | Author: | Crazy King | | File Size: | 277 | | Last Modified: | Feb 14 20:45:59 2007 |
| MD5 Checksum: | 16e6b55ea05f86589d5e907bb55a1866 |
|
| /// File Name: |
eway-xss.txt |
Description:
|
eWay suffers from a cross site scripting flaw.
| | Author: | BLacK ZeRo | | File Size: | 250 | | Last Modified: | Feb 14 20:44:29 2007 |
| MD5 Checksum: | daa8e5361cabc527eac5db7883dbaec5 |
|
| /// File Name: |
xssSplinder.txt |
Description:
|
www.splinder.com suffers from a cross site scripting flaw.
| | Author: | phoby | | File Size: | 478 | | Last Modified: | Feb 13 09:55:59 2007 |
| MD5 Checksum: | 9e3df0e96769862da94658ff66dfad86 |
|
| /// File Name: |
raditech-multiple.txt |
Description:
|
Raditech's Portal Search suffers from URL redirection and cross site scripting flaws.
| | Author: | Pedro Alexander Garcia | | File Size: | 1045 | | Last Modified: | Feb 13 09:54:19 2007 |
| MD5 Checksum: | e45af5ed58a3a10a2386a3abbba3e0f3 |
|
| /// File Name: |
mini-traverse.txt |
Description:
|
Miniwebsvr version 0.0.6 appears to be susceptible to a one level directory traversal flaw.
| | Author: | Daniel Nystrom, Fredrik Wessberg | | File Size: | 273 | | Last Modified: | Feb 13 09:49:05 2007 |
| MD5 Checksum: | 782d565e5e78814c9a75aeeaa184aaa2 |
|
|
|
|
|