Section: .. / 0701-exploits /
| /// File Name: |
nwomtopsites30-sql.txt |
Description:
|
Nwom Topsites version 3.0 is susceptible to SQL injection and cross site scripting vulnerabilities.
| | Author: | Luny | | File Size: | 259 | | Last Modified: | Jan 13 19:29:01 2007 |
| MD5 Checksum: | a902b5a13a9217877f9317c79f189958 |
|
| /// File Name: |
digi-sql.txt |
Description:
|
DigiAffiliate versions 1.4 and below remote SQL injection exploit that makes use of visu_user.asp.
| | Author: | ajann | | File Size: | 3474 | | Last Modified: | Jan 13 19:05:49 2007 |
| MD5 Checksum: | 58aa58089822af0d14929c8afa15cc6a |
|
| /// File Name: |
snews1530.txt |
Description:
|
sNews versions 1.5.30 and below remote administrative password reset and code execution exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 7276 | | Last Modified: | Jan 13 19:04:01 2007 |
| MD5 Checksum: | 10535134604269d44b7651ac784cfc44 |
|
| /// File Name: |
lunar-rfi.txt |
Description:
|
LunarPoll version 1.0 suffers from a remote file inclusion vulnerability.
| | Author: | ilker Kandemir | | Homepage: | http://ayyildiz.org/ | | File Size: | 734 | | Last Modified: | Jan 13 19:02:07 2007 |
| MD5 Checksum: | 746a786cff33a813f035acc31244b376 |
|
| /// File Name: |
tlm-rfi.txt |
Description:
|
TLM CMS versions 1.1 and below suffer from a remote file inclusion vulnerability.
| | Author: | GolD_M | | File Size: | 1681 | | Last Modified: | Jan 13 19:01:05 2007 |
| MD5 Checksum: | eda173b0a50608ae27ba01a380445f34 |
|
| /// File Name: |
mint-sql.txt |
Description:
|
Mint Haber Sistemi version 2.7 suffers from a remote SQL injection vulnerability.
| | Author: | chernobile | | Homepage: | http://www.cyber-sabotage.org | | File Size: | 641 | | Last Modified: | Jan 13 18:59:54 2007 |
| MD5 Checksum: | f91f3dc1d7e503fc7fcabefda20491f8 |
|
| /// File Name: |
raise.c |
Description:
|
Microsoft Vista NTRaiseHardError privilege escalation exploit.
| | Author: | erasmus | | File Size: | 8030 | | Last Modified: | Jan 13 18:58:06 2007 |
| MD5 Checksum: | a5f59c0f262a7ee799d17a6b320d81c0 |
|
| /// File Name: |
berlios.meta.txt |
Description:
|
This Metasploit module exploits a format string vulnerability in the Berlios GPSD server. This vulnerability was discovered by Kevin Finisterre.
| | Author: | senotier@enseirb.fr | | File Size: | 3476 | | Last Modified: | Jan 13 18:56:57 2007 |
| MD5 Checksum: | 484e7a591e8ea80dd8ad2f5352e1486e |
|
| /// File Name: |
filecopa.meta.txt |
Description:
|
This Metasploit module exploits the buffer overflow found in the LIST command in fileCOPA FTP server pre 18 Jul 2006 version discovered by www.appsec.ch.
| | Author: | acaro | | File Size: | 3519 | | Last Modified: | Jan 13 18:55:18 2007 |
| MD5 Checksum: | a2ae6fee2fa0a5bfd82c7132880df591 |
|
| /// File Name: |
navicopa.meta.txt |
Description:
|
This Metasploit module exploits a classical stack overflow in Navicopa Web Server 2.01 version. Credit to h07 for the discovery of this vulnerability. This is a port to the original h07 c code.
| | Author: | acaro | | File Size: | 2653 | | Last Modified: | Jan 13 18:54:08 2007 |
| MD5 Checksum: | fa87642387987833c8864f03a9fb99c1 |
|
| /// File Name: |
arcserve.py.txt |
Description:
|
CA BrightStor ARCserver tapeeng.exe remote buffer overflow exploit for Windows 2000 that binds a shell to port 4443.
| | Author: | Winny Thomas | | File Size: | 3998 | | Last Modified: | Jan 13 18:52:16 2007 |
| MD5 Checksum: | 817658b2c1c984fa07f10f765cb0c1b6 |
|
| /// File Name: |
quicktime.py.txt |
Description:
|
Apple Quicktime buffer overflow exploit for Windows 2000 that makes use of the rtsp URL Handler vulnerability. The qtl file created binds a shell to port 4444.
| | Author: | Winny Thomas | | File Size: | 5441 | | Last Modified: | Jan 13 18:50:57 2007 |
| MD5 Checksum: | 51d995851bd0dc9a0de491a88ff8fe21 |
|
| /// File Name: |
wmfdos.txt |
Description:
|
WMF proof of concept denial of service exploit.
| | Author: | cyanid-E | | File Size: | 617 | | Last Modified: | Jan 13 18:47:32 2007 |
| MD5 Checksum: | a70607a5bae12632f5c0d6345780aba2 |
|
| /// File Name: |
jshop13-rfi.txt |
Description:
|
Jshop Server version 1.3 suffers from a remote file inclusion vulnerability.
| | Author: | irvian | | File Size: | 608 | | Last Modified: | Jan 13 18:40:43 2007 |
| MD5 Checksum: | 80f96f48892c875308cc20c20d6e42cb |
|
| /// File Name: |
eiq-dos.txt |
Description:
|
Remote exploitation of a null pointer dereference exception allows for remote attackers to crash the EIQ Network Security Analyzer DataCollector service. Proof of concept code included.
| | Author: | Ethan Hunt | | File Size: | 2250 | | Last Modified: | Jan 13 18:39:57 2007 |
| MD5 Checksum: | f3b7362c12eb882f06fbaf7707f94a45 |
|
| /// File Name: |
cscart133-rfi.txt |
Description:
|
CS-Cart version 1.3.3 suffers from a remote file inclusion vulnerability in install.php.
| | Author: | irvian | | File Size: | 816 | | Last Modified: | Jan 13 18:23:45 2007 |
| MD5 Checksum: | 46ab790d6c3376ec794e0e964a773de8 |
|
| /// File Name: |
sazcart-rfi.txt |
Description:
|
sazcart version 1.5 suffers from a remote file inclusion vulnerability in cart.php.
| | Author: | IbnuSina | | File Size: | 711 | | Last Modified: | Jan 13 18:23:02 2007 |
| MD5 Checksum: | 2795204313ffe7728ef959c38789ad12 |
|
| /// File Name: |
editx-rfi.txt |
Description:
|
edit x suffers from a remote file inclusion flaw.
| | Author: | IbnuSina | | File Size: | 740 | | Last Modified: | Jan 13 18:19:10 2007 |
| MD5 Checksum: | 5b18eb4e24b8c1896ee64602e69c827a |
|
| /// File Name: |
ppc-rfi.txt |
Description:
|
ppc engine suffers from a remote file inclusion flaw.
| | Author: | IbnuSina | | File Size: | 2916 | | Last Modified: | Jan 13 17:55:04 2007 |
| MD5 Checksum: | 96815d24c4045e92fc84f60919eee714 |
|
| /// File Name: |
createauction-rfi.txt |
Description:
|
createauction suffers from a remote file inclusion flaw.
| | Author: | IbnuSina | | File Size: | 3583 | | Last Modified: | Jan 13 17:53:26 2007 |
| MD5 Checksum: | d2fb41e3b8858ac1e893dec88321ec31 |
|
| /// File Name: |
ebp2x-rfi.txt |
Description:
|
Easy Banner Pro version 2.x suffers from a remote file inclusion vulnerability.
| | Author: | rUnViRuS | | Homepage: | http://www.sec-area.com/ | | File Size: | 1684 | | Last Modified: | Jan 13 17:51:32 2007 |
| MD5 Checksum: | 2ff922507439118ead78bc86c203e733 |
|
| /// File Name: |
MOAB-12-01-2007.dmg.gz |
Description:
|
Month of Apple Bugs - Exploit that demonstrates a denial of service in the UFS filesystem. A specially crafted UFS filesystem in a DMG image can cause the ufs_lookup() function to call ufs_dirbad() when a corrupted directory entry is being read, leading to a kernel panic (denial of service). This issue cannot be abused for remote code execution.
| | Homepage: | http://projects.info-pull.com/moab/index.html | | File Size: | 8828 | | Last Modified: | Jan 13 17:48:50 2007 |
| MD5 Checksum: | 5e7418b5e7e4398e8fadcdaf873b1bcf |
|
| /// File Name: |
MOAB-11-01-2007.dmg.gz |
Description:
|
Month of Apple Bugs - Exploit for the byte_swap_sbin() function. The byte_swap_sbin() function, one of the UFS byte swapping routines (this code is not present in FreeBSD and it's Mac OS X XNU-specific; used for compatibility of filesystem streams between little and big-endian systems) is affected by a integer overflow vulnerability, leading to an exploitable denial of service condition.
| | Homepage: | http://projects.info-pull.com/moab/index.html | | File Size: | 835070 | | Last Modified: | Jan 13 17:47:37 2007 |
| MD5 Checksum: | fe61ab655bf2a2ba55995d71e5e89eaa |
|
| /// File Name: |
MOAB-10-01-2007.dmg.gz |
Description:
|
Month of Apple Bugs - Exploit for the ffs_mountfs() function. The ffs_mountfs() function, part of the UFS filesystem handling code (shared between FreeBSD and Mac OS X XNU) is affected by an integer overflow vulnerability, leading to an exploitable denial of service condition and potential arbitrary code execution.
| | Homepage: | http://projects.info-pull.com/moab/index.html | | File Size: | 900437 | | Last Modified: | Jan 13 17:46:40 2007 |
| MD5 Checksum: | 9fded174a03c49567839f12fb507720d |
|
| /// File Name: |
MOAB-09-01-2007.dmg |
Description:
|
Month of Apple Bugs - Exploit for a vulnerability in Finder. Finder is affected by a memory corruption vulnerability, which leads to an exploitable denial of service condition and potential arbitrary code execution, that can be triggered by DMG images. One of two exploits.
| | Author: | LMH | | Homepage: | http://projects.info-pull.com/moab/index.html | | Related Exploit: | MOAB-09-01-2007.rb.txt | | File Size: | 204800 | | Last Modified: | Jan 13 17:45:39 2007 |
| MD5 Checksum: | a6a5c160414d7278e288b1c921280d61 |
|
|
|
|
|