Section: .. / 0707-exploits /
| /// File Name: |
indexscript-sql.txt |
Description:
|
IndexScript versions 2.8 and below suffer from a SQL injection vulnerability in showcat.php.
| | Author: | xssvgamer | | File Size: | 404 | | Last Modified: | Jul 26 01:02:03 2007 |
| MD5 Checksum: | 84ed3858ab54e0ba79ab6205b63626a6 |
|
| /// File Name: |
internic-xss.txt |
Description:
|
InterNIC's whois look-up suffers from a cross site scripting vulnerability.
| | Author: | Tosser | | File Size: | 461 | | Last Modified: | Jul 31 02:20:35 2007 |
| MD5 Checksum: | 52c69f700bb337b3ca1c369b766a3d6f |
|
| /// File Name: |
ipswitch-overflow.txt |
Description:
|
IPSwitch IMail server 2006 SEARCH remote stack overflow exploit. Binds a shell to port 1154.
| | Author: | ZhenHan.Liu | | Homepage: | http://www.ph4nt0m.org/ | | File Size: | 5764 | | Last Modified: | Jul 26 01:04:01 2007 |
| MD5 Checksum: | 5aec044f25a17b719729eb54cd242c04 |
|
| /// File Name: |
isb05-sql.txt |
Description:
|
Insane Simple Blog versions 0.5 and below suffer from cross site scripting and SQL injection vulnerabilities.
| | Author: | Joseph Giron | | File Size: | 1093 | | Last Modified: | Jul 18 00:01:22 2007 |
| MD5 Checksum: | e78cc1bb3c7167aa21113794f6dea099 |
|
| /// File Name: |
itcms-xss.txt |
Description:
|
itcms version 0.2 suffers from a cross site scripting vulnerability.
| | Author: | You_You | | Homepage: | http://www.Aria-security.net | | File Size: | 412 | | Last Modified: | Jul 31 00:47:13 2007 |
| MD5 Checksum: | e45473f36c260d6eef3c0814cd273d4e |
|
| /// File Name: |
jblog-xss.txt |
Description:
|
JBlog version 1.0 suffers from cross site scripting and administrator creation vulnerabilities.
| | Author: | S4mi | | File Size: | 5101 | | Last Modified: | Jul 23 00:07:14 2007 |
| MD5 Checksum: | bfe1ce303743a1f329f3675b8d47b6aa |
|
| /// File Name: |
jgaa-sql.txt |
Description:
|
jgaa remote SQL injection exploit that allows administrator password hash retrieval.
| | Author: | fl0 fl0w | | File Size: | 3336 | | Last Modified: | Jul 25 00:01:19 2007 |
| MD5 Checksum: | 95488946d13db8bdf40d635e71aeaba0 |
|
| /// File Name: |
jnlp-overflow.txt |
Description:
|
Sun Java WebStart JNLP stack buffer overflow denial of service exploit.
| | Author: | ZhenHan.Liu | | Homepage: | http://www.ph4nt0m.org/ | | File Size: | 5338 | | Last Modified: | Jul 11 02:17:50 2007 |
| MD5 Checksum: | 40de6e961aa501015d4647780efe3a7e |
|
| /// File Name: |
joomla-sql.txt |
Description:
|
Joomla version 1.0.12 suffers from a SQL injection vulnerability.
| | Author: | HACKERS PAL | | Homepage: | http://www.soqor.net/ | | File Size: | 934 | | Last Modified: | Jul 31 01:34:25 2007 |
| MD5 Checksum: | 1dcc59039c372abdfe8738d8e1657d81 |
|
| /// File Name: |
joomlaexpose-rfu.txt |
Description:
|
The Joomla component Expose versions RC35 and below suffer from a remote permission bypass and file upload vulnerability.
| | Author: | Cold z3ro | | Homepage: | http://www.hack-teach.com/ | | File Size: | 3562 | | Last Modified: | Jul 19 00:18:21 2007 |
| MD5 Checksum: | 06baad934f99d9743d1b9e55d3233198 |
|
| /// File Name: |
joomlapony-sql.txt |
Description:
|
Joomla component Pony Gallery versions 1.5 and below are susceptible to a blind SQL injection exploit that makes use of index.php.
| | Author: | ajann | | File Size: | 1259 | | Last Modified: | Jul 20 01:51:58 2007 |
| MD5 Checksum: | 1c633f7eb95c6f0c68d6881d221fcfad |
|
| /// File Name: |
leventveysi-sql.txt |
Description:
|
Levent Veysi Portal version 1.0 suffers from a SQL injection vulnerability.
| | Author: | GeFORC3 | | Homepage: | http://WwW.GeFORC3.Org | | File Size: | 401 | | Last Modified: | Jul 7 01:31:58 2007 |
| MD5 Checksum: | b409ba8a66f93ab00323bb0658921455 |
|
| /// File Name: |
limesurvey-rfi.txt |
Description:
|
LimeSurvey version 1.49RC2 suffers from multiple remote file inclusion vulnerabilities.
| | Author: | Pr0T3cT10n | | Homepage: | http://www.kamikaz-team.com/ | | File Size: | 1542 | | Last Modified: | Jul 7 01:02:47 2007 |
| MD5 Checksum: | 8316b5829ec62d823e6dde3b809b0d83 |
|
| /// File Name: |
linkedin-overflow.txt |
Description:
|
LinkedIn Toolbar version 3.0.2.1098 remote buffer overflow exploit.
| | Author: | Jared DeMott | | File Size: | 1289 | | Last Modified: | Jul 25 00:39:04 2007 |
| MD5 Checksum: | 13861dc8b511010ec836f8f370c836d5 |
|
| /// File Name: |
linpha131-sql.txt |
Description:
|
LinPHA versions 1.3.1 and below remote blind SQL injection exploit that makes use of new_images.php.
| | Author: | EgiX | | File Size: | 6506 | | Last Modified: | Jul 31 00:15:12 2007 |
| MD5 Checksum: | d3838baf9474200047b3e0e616b2e435 |
|
| /// File Name: |
linux-26202.txt |
Description:
|
Linux kernel IPV6_Getsockopt_Sticky memory leak proof of concept exploit. This affects versions below 2.6.20.2.
| | Author: | dreyer | | File Size: | 2107 | | Related CVE(s): | CVE-2007-1000 | | Last Modified: | Jul 11 03:13:59 2007 |
| MD5 Checksum: | 181354724a1931cfa3e703c382761aed |
|
| /// File Name: |
lotus-overflow.txt |
Description:
|
Lotus Domino IMAP4 server version 6.5.4 / Windows 2000 Advanced Server x86 remote buffer overflow exploit.
| | Author: | Dominic Chell, prdelka | | File Size: | 7038 | | Last Modified: | Jul 20 22:30:19 2007 |
| MD5 Checksum: | c034bc24a2ccbd22b9171961180e067a |
|
| /// File Name: |
lsa_transnames_heap-linux.rb.txt |
Description:
|
This Metasploit module triggers a heap overflow in the LSA RPC service of the Samba daemon. This module uses the TALLOC chunk overwrite method (credit Ramon and Adriano), which only works with Samba versions 3.0.21 through 3.0.24. Additionally, this module will not work when the Samba "log level" parameter is higher than "2". Linux version.
| | Author: | Ramon de Carvalho Valle, Adriano Lima, H D Moore | | Homepage: | http://www.risesecurity.org/ | | File Size: | 8017 | | Related CVE(s): | CVE-2007-2446 | | Last Modified: | Jul 26 02:00:21 2007 |
| MD5 Checksum: | 4f3d9021ab7aeab8ee51f9ee5605ad0c |
|
| /// File Name: |
lsa_transnames_heap-solaris.rb.txt |
Description:
|
This Metasploit module triggers a heap overflow in the LSA RPC service of the Samba daemon. This module uses the TALLOC chunk overwrite method (credit Ramon and Adriano), which only works with Samba versions 3.0.21 through 3.0.24. Additionally, this module will not work when the Samba "log level" parameter is higher than "2". Solaris version.
| | Author: | Ramon de Carvalho Valle, Adriano Lima, H D Moore | | Homepage: | http://www.risesecurity.org/ | | File Size: | 5515 | | Related CVE(s): | CVE-2007-2446 | | Last Modified: | Jul 26 02:04:19 2007 |
| MD5 Checksum: | 9f07c9cd8fd013c9608f103024c1c839 |
|
| /// File Name: |
m3ks-adv-24.7.07.txt |
Description:
|
PhpHostBot suffers from a remote file inclusion vulnerability in login_form.
| | Author: | S4M3K | | Homepage: | http://www.m3ks.org/ | | File Size: | 1043 | | Last Modified: | Jul 27 21:32:14 2007 |
| MD5 Checksum: | 30abc3c86e83e38cf35bb6b6ca459810 |
|
| /// File Name: |
madoa-rfi.txt |
Description:
|
Madoa Poll version 1.1 suffers from a remote file inclusion vulnerability.
| | Author: | Ilker Kandemir | | File Size: | 424 | | Last Modified: | Jul 31 01:05:22 2007 |
| MD5 Checksum: | b752aa4c28bf500442b26255f8f4498e |
|
| /// File Name: |
mailmachine-lfi.txt |
Description:
|
Mail Machine versions 3.989 and below suffer from a local file inclusion vulnerability.
| | Author: | H4 / Team XPK | | File Size: | 2469 | | Last Modified: | Jul 11 02:42:13 2007 |
| MD5 Checksum: | d4f1e431b180bb42b908180b52c32f4b |
|
| /// File Name: |
major_rls51.txt |
Description:
|
Virtual Hosting Control System (VHCS) versions 2.4.7.1 and below suffer from a session fixation issue.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 2003 | | Last Modified: | Jul 23 00:24:56 2007 |
| MD5 Checksum: | 1cd624b692b6801508ec08ff978198ce |
|
|
|
|
|