Section: .. / 0512-exploits /
| /// File Name: |
2005-exploits.tgz |
Description:
|
Complete comprehensive archive of all exploits posted to Packet Storm for 2005.
| | Homepage: | http://packetstormsecurity.org/ | | File Size: | 8651192 | | Last Modified: | Jan 1 16:41:27 2006 |
| MD5 Checksum: | ae68a5b0cc2feaed42dba3d2307fbc66 |
|
| /// File Name: |
ie_xp_pfv_metafile.pm.txt |
Description:
|
This Metasploit module exploits a vulnerability in the Windows Picture and Fax Viewer found in Windows XP and 2003. This vulnerability uses a corrupt Windows Metafile to execute arbitrary code.
| | Author: | H D Moore | | Homepage: | http://www.metasploit.com | | File Size: | 50588 | | Last Modified: | Dec 31 03:59:58 2005 |
| MD5 Checksum: | 41f7cfba418309a3d955d808ee079bd6 |
|
| /// File Name: |
k-rad3.c |
Description:
|
Linux kernel 2.6.11 and below CPL 0 local exploit. Third version/variant of this exploit.
| | Author: | sd, alert7 | | Homepage: | http://www.xfocus.org/ | | File Size: | 17113 | | Last Modified: | Dec 31 04:05:55 2005 |
| MD5 Checksum: | fe97c08a01073659a768232db8f502ef |
|
| /// File Name: |
zencart_126d_xpl.html |
Description:
|
Zen-Cart versions 1.2.6d and below are susceptible to blind SQL injection and remote command execution attacks. Exploit included.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 16138 | | Last Modified: | Dec 3 01:22:36 2005 |
| MD5 Checksum: | a507099ecbfb1ccd22d23ed6ed3eca57 |
|
| /// File Name: |
PHPGedView.php.txt |
Description:
|
PHPGedView versions less than or equal to 3.3.7 arbitrary local and remote code execution and php injection exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 15014 | | Last Modified: | Dec 28 15:40:01 2005 |
| MD5 Checksum: | 1c536361235cf3a330b3e3b7f98d107f |
|
| /// File Name: |
wbaker_260_xpl.txt |
Description:
|
Website Baker versions 2.6.0 and below suffer from SQL injection, login bypass, and remote code execution flaws. Exploit included.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 14910 | | Last Modified: | Dec 13 23:57:16 2005 |
| MD5 Checksum: | f51d6a97733a1d4570932cc029123f2c |
|
| /// File Name: |
Bb_6.zip |
Description:
|
Blackboard versions 6.3.1.424 and 6.2.3.23 (and possibly earlier versions) are susceptible to login bypass, spoofing of announcements, and proxying flaws.
| | Author: | dr_insane | | File Size: | 13454 | | Last Modified: | Dec 14 01:36:44 2005 |
| MD5 Checksum: | 7113f857a7b23c9e90395e557919c2c2 |
|
| /// File Name: |
flatnuke256_xpl.txt |
Description:
|
Flatnuke version 2.5.6 privilege escalation and remote command execution exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 12931 | | Last Modified: | Dec 14 01:31:26 2005 |
| MD5 Checksum: | 0b914d4061a58677e535436986fc8701 |
|
| /// File Name: |
Dev_15_sql_xpl.php.txt |
Description:
|
Dev Web versions less than of equal to 1.5 'cat' SQL injection and admin MD5 password hash disclosure exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 12762 | | Last Modified: | Dec 28 19:47:54 2005 |
| MD5 Checksum: | 4e8ecca6f99911710c2e7703c1042181 |
|
| /// File Name: |
limbo1042_xpl.txt |
Description:
|
LIMBO CMS versions 1.0.4.2 and below suffer from blind SQL injection, cross site scripting, local file inclusion, remote code execution, and other fun flaws. Exploit provided.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 12178 | | Last Modified: | Dec 15 01:56:37 2005 |
| MD5 Checksum: | 7ffea299a93e6527c9cced8875eb9513 |
|
| /// File Name: |
mambo452_xpl.html |
Description:
|
Mambo versions 4.5.2 and below Globals overwrite and remote command execution exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 10846 | | Last Modified: | Dec 9 11:14:28 2005 |
| MD5 Checksum: | 6d5cda257b3443d29067a4e7e9e83872 |
|
| /// File Name: |
sugar_suite_40beta.txt |
Description:
|
SugarSuite Open Source versions 4.0beta and below suffer from remote code execution and file inclusion flaws. Exploit provided.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 10408 | | Last Modified: | Dec 13 23:19:41 2005 |
| MD5 Checksum: | ff2fa3cc8d3377e7cc559a9c0fb94fc3 |
|
| /// File Name: |
SEC-20051211-0.txt |
Description:
|
SEC-CONSULT Security Advisory 20051211-0 - Horde versions 3.0.7 and below, Kronolith versions 2.0.5 and below, Mnemo version 2.0.2 and below, Nag versions 2.0.3 and below, and Turba versions 2.0.4 and below are susceptible to cross site scripting attacks.
| | Author: | Johannes Greil | | Homepage: | http://www.sec-consult.com | | File Size: | 8439 | | Last Modified: | Dec 14 02:16:06 2005 |
| MD5 Checksum: | cd3e50c6d30cf26aab9c6ebd6280f69c |
|
| /// File Name: |
mIRCexploitXPSP2eng.c |
Description:
|
mIRC exploit for versions 6.16 and below. Proof of concept exploit that does not actually increase privileges but could be useful in restricted environments.
| | Author: | Jordi Corrales | | File Size: | 7749 | | Last Modified: | Dec 28 17:23:55 2005 |
| MD5 Checksum: | f42e9afc57363d0249b6b3aa0790d5ed |
|
| /// File Name: |
gmailXSSinject.txt |
Description:
|
Google's GMailSite script is susceptible to cross site scripting attacks. Details provided. Versions 1.0.4 and below are affected.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 7393 | | Last Modified: | Dec 30 21:24:35 2005 |
| MD5 Checksum: | b30b60462a746c3ee07d8b8ef9512402 |
|
| /// File Name: |
appfluent.txt |
Description:
|
Appfluent Database IDS version 2.0 suffers from an environment variable overflow that can be manipulated using sudo as an attack vector. Exploit provided.
| | Author: | c0ntex | | Homepage: | http://www.open-security.org | | File Size: | 6908 | | Last Modified: | Dec 13 23:21:23 2005 |
| MD5 Checksum: | 32c5b58d9d21114244ca445df9985b02 |
|
| /// File Name: |
lyris-listmanager.txt |
Description:
|
The Lyris ListManager software versions 5.0 through 8.8a are vulnerable to numerous SQL injection, source code disclosure, and authentication bypass flaws. Full details provided.
| | Author: | H D Moore | | Homepage: | http://metasploit.com/ | | Related Exploit: | lyris_attachment_mssql.pm.txt | | File Size: | 6050 | | Last Modified: | Dec 14 01:11:49 2005 |
| MD5 Checksum: | 82ab2ed7706e828cab1028eedd58814c |
|
| /// File Name: |
cerberusHelp.txt |
Description:
|
Cerberus HelpDesk is susceptible to SQL injection and cross site scripting flaws. cerberus-gui 2.649 is affected. support-center 2.649 through 3.2.0pr2 is also affected. Full exploitation details provided.
| | Author: | A. Ramos | | Homepage: | http://www.unsec.net | | File Size: | 5752 | | Last Modified: | Dec 27 03:31:57 2005 |
| MD5 Checksum: | 4e8068a82c40d05baeb62691157db870 |
|
|
|
|
|