Section: .. / 0705-exploits /
| /// File Name: |
blogme-sql.txt |
Description:
|
BlogMe version 3.0 suffers from a remote SQL injection vulnerability in archshow.asp.
| | Author: | gsy, kerem125 | | File Size: | 334 | | Last Modified: | May 16 19:38:21 2007 |
| MD5 Checksum: | 29b53ccf1a0086bc418a0d537377622c |
|
| /// File Name: |
boastmachine-session.txt |
Description:
|
BoastMachine version 3.0 Platinum suffers from a session hacking vulnerability.
| | Author: | Vagrant | | Homepage: | http://www.e-hack.org/ | | File Size: | 1018 | | Last Modified: | May 23 00:52:33 2007 |
| MD5 Checksum: | ceaeb242cb29a1a049e8c8c6eaea846c |
|
| /// File Name: |
btitracker-sql.txt |
Description:
|
BtiTracker versions 1.4.1 and below remote SQL injection exploit.
| | Author: | m@ge|ozz | | File Size: | 1087 | | Last Modified: | May 23 00:42:03 2007 |
| MD5 Checksum: | 084263b93cd61687265e3cb138ee3372 |
|
| /// File Name: |
BTP00000P000ZA.zip |
Description:
|
Proof of concept code that demonstrates a flaw with how ZoneAlarm uses process identifiers in Microsoft Windows allowing for complete bypass.
| | Homepage: | http://www.matousec.com/ | | Related File: | bypassing-pwf-hips.txt | | File Size: | 5126 | | Last Modified: | May 16 21:35:12 2007 |
| MD5 Checksum: | 8000bd70c5341bd4a19fe358e745fb1d |
|
| /// File Name: |
BTP00002P005CF.zip |
Description:
|
Proof of concept code that demonstrates a flaw with how Comodo Firewall uses process identifiers in Microsoft Windows allowing for complete bypass.
| | Homepage: | http://www.matousec.com/ | | Related File: | bypassing-pwf-hips.txt | | File Size: | 6268 | | Last Modified: | May 16 21:37:07 2007 |
| MD5 Checksum: | a52ac420ca7716f99be0fb512788583a |
|
| /// File Name: |
cabright-dos.txt |
Description:
|
CA BrightStor Backup version 11.5.2.0 caloggderd.exe remote denial of service exploit.
| | Author: | M. Shirk | | Homepage: | zhttp://www.shirkdog.us/ | | File Size: | 3536 | | Last Modified: | May 16 19:25:46 2007 |
| MD5 Checksum: | ec90ff9b9056adb8b217ca3ac0b396cb |
|
| /// File Name: |
cabright2-dos.txt |
Description:
|
CA BrightStor Backup version 11.5.2.0 Mediasvr.exe remote denial of service exploit.
| | Author: | M. Shirk | | Homepage: | zhttp://www.shirkdog.us/ | | File Size: | 4428 | | Last Modified: | May 16 19:26:24 2007 |
| MD5 Checksum: | c86c4b3e185d579ced0fa880cc5a5b96 |
|
| /// File Name: |
censura-sql.txt |
Description:
|
Censura version 1.15.04 suffers from a remote SQL injection vulnerability in censura.php.
| | Homepage: | http://www.cyber-security.org/ | | File Size: | 535 | | Last Modified: | May 4 11:29:42 2007 |
| MD5 Checksum: | aceee95a7074becc75bc9083a51863c7 |
|
| /// File Name: |
cgx-rfi.txt |
Description:
|
CGX 2005-03-14 suffers from remote file inclusion vulnerabilities.
| | Author: | GolD_M | | Homepage: | http://www.tryag.cc/ | | File Size: | 468 | | Last Modified: | May 9 23:26:47 2007 |
| MD5 Checksum: | 9dc6bd07d81b20bb222b19e747778347 |
|
| /// File Name: |
cisco-input.txt |
Description:
|
An input validation vulnerability exists in the Cisco CallManager version 4.1 and possibly in earlier versions as well.
| | Author: | Marc Ruef, Stefan Friedli | | Homepage: | http://www.scip.ch/ | | File Size: | 3841 | | Last Modified: | May 23 21:53:45 2007 |
| MD5 Checksum: | 559c7bb04a3696fea7955940aef04dfb |
|
| /// File Name: |
cjgexplorer-rfi.txt |
Description:
|
CJG Explorer Pro version 3.2 suffers from remote file inclusion vulnerabilities.
| | Author: | Mogatil | | File Size: | 1000 | | Last Modified: | May 16 19:39:37 2007 |
| MD5 Checksum: | c23b98723d31d4cd2ea4a14bd85fca63 |
|
| /// File Name: |
clever-overflow.txt |
Description:
|
Clever Database Comparer ActiveX version 2.2 remote buffer overflow proof of concept exploit.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 3278 | | Last Modified: | May 16 19:19:23 2007 |
| MD5 Checksum: | 8e0d41ac2102899db75f6cb8f2e4674d |
|
| /// File Name: |
CMSmadesimple-sql.txt |
Description:
|
CMS Made Simple version 1.05 is susceptible to a SQL injection vulnerability.
| | Author: | Daniel Lucq | | Homepage: | http://www.scanit.be/ | | File Size: | 1745 | | Last Modified: | May 3 03:26:26 2007 |
| MD5 Checksum: | 4c6fd5317d813ad7438c6869268e4346 |
|
| /// File Name: |
cpcommerce-sql.txt |
Description:
|
cpCommerce versions 1.1.0 and below remote SQL injection exploit that makes use of category.php.
| | Author: | Kacper | | Homepage: | http://www.rahim.webd.pl/ | | File Size: | 4352 | | Last Modified: | May 30 17:25:37 2007 |
| MD5 Checksum: | e5c6d92e6daff7c2e53a757a10d523e8 |
|
| /// File Name: |
CVE-2007-1355.txt |
Description:
|
The Tomcat documentation web application includes a sample application that contains multiple cross site scripting vulnerabilities. Versions affected include Tomcat 4.0.0 to 4.0.6, Tomcat 4.1.0 to 4.1.36, Tomcat 5.0.0 to 5.0.30, Tomcat 5.5.0 to 5.5.23, and Tomcat 6.0.0 to 6.0.10.
| | Author: | Mark Thomas | | File Size: | 996 | | Related CVE(s): | CVE-2007-1355 | | Last Modified: | May 21 21:45:13 2007 |
| MD5 Checksum: | 70a1d941130707c09a2c11a78f294760 |
|
| /// File Name: |
digirez-xss.txt |
Description:
|
Digirez version 3.4 suffers from cross site scripting vulnerabilities.
| | Author: | Linux_Drox | | Homepage: | http://www.LeZr.com | | File Size: | 438 | | Last Modified: | May 30 22:55:08 2007 |
| MD5 Checksum: | 073da0002be51c3f8355a2c6218f06e1 |
|
| /// File Name: |
dokeos165-sql.txt |
Description:
|
Dokeos versions 1.6.5 and below remote SQL injection exploit that makes use of courseLog.php.
| | Author: | Silentz | | Homepage: | http://www.w4ck1ng.com/ | | File Size: | 3674 | | Last Modified: | May 30 17:23:19 2007 |
| MD5 Checksum: | 3cae109dc0939d8936b2b607066b0c77 |
|
| /// File Name: |
dokeos180-sql.txt |
Description:
|
Dokeos versions 1.8.0 and below remote SQL injection exploit that makes use of my_progress.php.
| | Author: | Silentz | | Homepage: | http://www.w4ck1ng.com/ | | File Size: | 4403 | | Last Modified: | May 30 17:21:09 2007 |
| MD5 Checksum: | db1edf63914c57945396ed5a90f483c5 |
|
| /// File Name: |
dynamicpad-rfi.txt |
Description:
|
DynamicPAD versions 1.02.18 and below suffer from a remote file inclusion vulnerability.
| | Author: | ThE TiGeR | | File Size: | 339 | | Last Modified: | May 8 05:09:22 2007 |
| MD5 Checksum: | 2a02681cd45a6318c101339768c89357 |
|
| /// File Name: |
eannu-sql.txt |
Description:
|
E-Annu is susceptible to a SQL injection vulnerability in home.php.
| | Author: | Ilker Kandemir | | File Size: | 649 | | Last Modified: | May 3 01:34:18 2007 |
| MD5 Checksum: | 6dec74d55add798fb43d712cad0e69a5 |
|
|
|
|
|