Section: .. / 0601-exploits /
| /// File Name: |
ddsnSQL.txt |
Description:
|
DDSN is susceptible to SQL injection attacks via the login sequence.
| | Author: | khc | | File Size: | 739 | | Last Modified: | Jan 21 08:17:12 2006 |
| MD5 Checksum: | f20b868cba46e9332a90e1c8e440d970 |
|
| /// File Name: |
DMA-2006-0112a.txt |
Description:
|
Using ussp-push from the Toshiba Bluetooth Stack versions 4.00.23(T) and below, an attacker can place a trojaned file anywhere on the filesystem.
| | Author: | Kevin Finisterre | | Homepage: | http://www.digitalmunition.com/ | | File Size: | 3620 | | Last Modified: | Jan 15 17:54:17 2006 |
| MD5 Checksum: | 13c47dbcf05a5bc3f1fedca80adbb8b8 |
|
| /// File Name: |
drupal.txt |
Description:
|
Drupal is susceptible to cross site scripting attacks via IMG tags.
| | Author: | Liz0ziM | | Homepage: | http://www.biyo.tk | | File Size: | 1922 | | Last Modified: | Jan 3 03:46:39 2006 |
| MD5 Checksum: | 435c1a197381b2c0f151a3a79bf6cda4 |
|
| /// File Name: |
DSR-farmerswife44sp1.pl.txt |
Description:
|
Farmers WIFE version 4.4 sp1 ftpd remote exploit that allows for system compromise.
| | Author: | kokanin | | File Size: | 2957 | | Last Modified: | Jan 15 18:14:43 2006 |
| MD5 Checksum: | 8f952e01a07259244b3b2baf44fe55e3 |
|
| /// File Name: |
eggblog-sql.txt |
Description:
|
eggblog v2.0 is vulnerable to XSS and SQL injection.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1177 | | Last Modified: | Jan 25 08:51:02 2006 |
| MD5 Checksum: | e06afd90aa34dde57e03d9993b8c3647 |
|
| /// File Name: |
eStara.c |
Description:
|
eStara Softphone buffer overflow exploit that makes use of a vulnerability in the SIP stack processing. Versions 3.0.1.14 and 3.0.1.46 were verified vulnerable.
| | Author: | Zwell | | Homepage: | http://www.donews.net/zwell | | File Size: | 30925 | | Last Modified: | Jan 12 02:05:37 2006 |
| MD5 Checksum: | a8e48d754d17cc984698828026578bb6 |
|
| /// File Name: |
EV0001.txt |
Description:
|
VEGO Web Forum versions 1.26 and below suffer from SQL injection flaws. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1541 | | Last Modified: | Jan 4 05:34:04 2006 |
| MD5 Checksum: | 0ac527c4e0ac44134a4a7114cd55dc14 |
|
| /// File Name: |
EV0002.txt |
Description:
|
VEGO Links Builder version 2.0 suffers from a SQL injection flaw. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 972 | | Last Modified: | Jan 4 05:35:04 2006 |
| MD5 Checksum: | f49b036b4313d32d340ecf3120295932 |
|
| /// File Name: |
EV0003.txt |
Description:
|
oaBoard version 1.0 suffers from a remote php include and execution flaw. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 912 | | Last Modified: | Jan 4 05:36:06 2006 |
| MD5 Checksum: | f04ea6970108e626932bebd68e851346 |
|
| /// File Name: |
EV0004.txt |
Description:
|
Chipmunk Guestbook versions 1.4 and below suffer from a cross site scripting flaw. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1079 | | Last Modified: | Jan 4 05:37:03 2006 |
| MD5 Checksum: | 428b07a8f3feee943c2022a41e2dc2f8 |
|
| /// File Name: |
EV0005.txt |
Description:
|
PHPenpals version 310704 suffers from a SQL injection flaw in profile.php. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1036 | | Last Modified: | Jan 4 05:38:16 2006 |
| MD5 Checksum: | 6f79885444231de57267c05ea2925576 |
|
| /// File Name: |
EV0006.txt |
Description:
|
phpBook versions 1.3.2 and below suffer from a php code execution flaw due to an unsanitized variable. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 909 | | Last Modified: | Jan 4 05:39:06 2006 |
| MD5 Checksum: | b122a4b3240ffbe2b36aae734f74775c |
|
| /// File Name: |
EV0007.txt |
Description:
|
Chimera Web Portal System version 0.2 is susceptible to SQL injection and cross site scripting attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1505 | | Last Modified: | Jan 4 05:40:01 2006 |
| MD5 Checksum: | d1b0ac8378f55aebcccf71d22f4738a1 |
|
| /// File Name: |
EV0008.txt |
Description:
|
inTouch 0.5.1 Alpha is susceptible to SQL injection attacks via the login page. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 975 | | Last Modified: | Jan 4 05:40:41 2006 |
| MD5 Checksum: | 06bfd3cd16d5efa0cf2668fa307934a2 |
|
| /// File Name: |
EV0009.txt |
Description:
|
PHPjournaler version 1.0 is susceptible to SQL injection attacks via index.php. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1021 | | Last Modified: | Jan 4 05:41:21 2006 |
| MD5 Checksum: | ba8cd3f4d615b26d13a8ea614dcca1e6 |
|
| /// File Name: |
EV0010.txt |
Description:
|
B-net Software version 1.0 is susceptible to cross site scripting attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1185 | | Last Modified: | Jan 4 06:09:07 2006 |
| MD5 Checksum: | 8e8f514602094834d3eb15a736e18fff |
|
| /// File Name: |
EV0011.txt |
Description:
|
ScozBook version BETA 1.1 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1154 | | Last Modified: | Jan 4 06:09:45 2006 |
| MD5 Checksum: | b44ed22d773155b59a9f51328ccdc751 |
|
| /// File Name: |
EV0014.txt |
Description:
|
TinyPHPForum versions 3.6 and below suffer from directory traversal, cross site scripting, and information disclosure flaws. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1337 | | Last Modified: | Jan 8 03:24:34 2006 |
| MD5 Checksum: | 90693ed76e197a01401b1c05b494c36b |
|
| /// File Name: |
EV0015.txt |
Description:
|
ADNForum version 1.0b is susceptible to SQL injection and cross site scripting vulnerabilities. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1427 | | Last Modified: | Jan 8 06:15:20 2006 |
| MD5 Checksum: | f56b32e64169be4a853e63ddc387ecdb |
|
| /// File Name: |
EV0016.txt |
Description:
|
Proyecto Domus version 2.10 is susceptible to a cross site scripting vulnerability. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1127 | | Last Modified: | Jan 8 06:30:18 2006 |
| MD5 Checksum: | afec9a648f52c5327ffda04fcbe5ce4e |
|
| /// File Name: |
EV0017.txt |
Description:
|
TheWebForum version 1.2.1 is susceptible to cross site scripting and SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1693 | | Last Modified: | Jan 8 06:35:14 2006 |
| MD5 Checksum: | bae4e106cc7612ff061fa6c458a550d0 |
|
| /// File Name: |
EV0018.txt |
Description:
|
427BB versions 2.2 and 2.2.1 are susceptible to cookie-based authentication bypass, SQL injection, and cross site scripting attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1914 | | Last Modified: | Jan 10 05:11:01 2006 |
| MD5 Checksum: | 48c087b5e1986dea3c9e6141391d6172 |
|
| /// File Name: |
EV0019.txt |
Description:
|
NavBoard BBcode version 16 Stable (2.6.0) is susceptible to cross site scripting attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1387 | | Last Modified: | Jan 8 19:28:12 2006 |
| MD5 Checksum: | 795dcec7a4b3981f729c758dd838b026 |
|
|
|
|
|