Section: .. / 0607-exploits /
| /// File Name: |
ms-w0rd.c |
Description:
|
Microsoft Word exploit that produces a .doc file that demonstrates a memory access violation. Affected are versions 2003, 2002, 2000.
| | Author: | naveed afzal | | File Size: | 260564 | | Last Modified: | Jul 9 08:53:08 2006 |
| MD5 Checksum: | b66bde4a8cef907874cc011abd712850 |
|
| /// File Name: |
bl4ck_ms06_036.tgz |
Description:
|
Functioning remote exploit for the Windows DHCP Client broadcast attack vulnerability as described in MS06-036.
| | Author: | redsand | | Homepage: | http://www.blacksecurity.org/ | | File Size: | 246171 | | Last Modified: | Jul 24 01:54:49 2006 |
| MD5 Checksum: | df91ae131f9a0b4d0a1877881ddee8d6 |
|
| /// File Name: |
mspp-poc3.txt |
Description:
|
Microsoft Power Point memory corruption vulnerability proof of concept exploit.
| | Author: | naveed afzal | | File Size: | 72718 | | Last Modified: | Jul 15 04:52:31 2006 |
| MD5 Checksum: | 21194effb168bf2b1a43b78941ec3cd7 |
|
| /// File Name: |
mspp-poc2.txt |
Description:
|
Microsoft Power Point mso.dll vulnerability proof of concept exploit.
| | Author: | naveed afzal | | File Size: | 72647 | | Last Modified: | Jul 15 04:51:50 2006 |
| MD5 Checksum: | eb7dabe9c19efae173c9b32311e92666 |
|
| /// File Name: |
mspp-poc1.txt |
Description:
|
Microsoft Power Point unspecified vulnerability proof of concept exploit.
| | Author: | naveed afzal | | File Size: | 72570 | | Last Modified: | Jul 15 04:51:15 2006 |
| MD5 Checksum: | d89a30648b4d923506af2f7a2c07193b |
|
| /// File Name: |
Excel-Hlink_Exploit_Fr.cpp |
Description:
|
Microsoft Excel 2000 and 2003 exploit for WinXP SP2 French. Microsoft Excel is prone to a remote code execution issue which may be triggered when a malformed Excel document is opened. The issue is due to an error in Excel while handling malformed URL strings.
| | Author: | NSRocket | | File Size: | 30319 | | Last Modified: | Jul 9 07:57:31 2006 |
| MD5 Checksum: | 65fa59a59588a24ebca203d9d567cfd7 |
|
| /// File Name: |
msieDoS.txt |
Description:
|
Microsoft Internet Explorer suffers from a denial of service flaw using the Content-Type directive.
| | Author: | Firestorm | | File Size: | 29836 | | Last Modified: | Jul 24 02:17:46 2006 |
| MD5 Checksum: | 2fd8f8e614dfbd62768f637981322acd |
|
| /// File Name: |
mimesweeperXSS.txt |
Description:
|
MIMESweeper For Web version 5.x suffers from a cross site scripting flaw.
| | Author: | Erez Metula | | File Size: | 24647 | | Last Modified: | Jul 12 04:16:44 2006 |
| MD5 Checksum: | 9c4419ed27f083c741505eb0a9857fcf |
|
| /// File Name: |
r57ipb216gui.txt |
Description:
|
Invision Power Board v2.1 versions less than or equal to 2.1.6 SQL injection exploit.
| | Author: | RST/GHC | | Homepage: | http://rst.void.ru | | File Size: | 16377 | | Last Modified: | Jul 18 17:14:53 2006 |
| MD5 Checksum: | da8987af9143e82f84a9f7ba81ccd624 |
|
| /// File Name: |
msword-hlink-ohday.txt |
Description:
|
Microsoft Word local hlink exploit. Written for Word 2000 and XP. Binds a shell on port 49152.
| | Author: | SYS 49152 | | File Size: | 16118 | | Last Modified: | Jul 12 04:19:48 2006 |
| MD5 Checksum: | 3d9821b97776ea58e75eb89cae9ce3e0 |
|
| /// File Name: |
Achilles.c |
Description:
|
Modified version of the Achilles Windows Attack Tool that Microsoft claims does not demonstrate a denial of service vulnerability.
| | Author: | J. Oquendo | | File Size: | 15715 | | Last Modified: | Jul 26 04:02:09 2006 |
| MD5 Checksum: | 09be96124ac6f49ce252534b1ec8b74f |
|
| /// File Name: |
gdiplus.pl.txt |
Description:
|
Gidplus.dll division by 0 proof of concept exploit.
| | Author: | Mr.Niega | | File Size: | 15355 | | Last Modified: | Aug 3 01:19:26 2006 |
| MD5 Checksum: | 49da58624b1e2f6dd3e7adaf58bd50a4 |
|
| /// File Name: |
etomiteCMS-061.txt |
Description:
|
Etomite CMS versions 0.6.1 and below remote command execution exploit making use of rfiles.php.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 9447 | | Last Modified: | Jul 27 21:32:21 2006 |
| MD5 Checksum: | 925bd46d64d6aa658bff0d26783d6506 |
|
| /// File Name: |
pivot130rc2.php.txt |
Description:
|
Pivot versions 1.30 RC2 and below privilege escalation and remote command execution exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 9437 | | Last Modified: | Jul 9 08:43:12 2006 |
| MD5 Checksum: | d95cfa7d604b7c850bf356f26b8ec7b8 |
|
| /// File Name: |
BTFs_MSWorksSpreadsheet_PoCFiles.zi..> |
Description:
|
Proof of concept exploits that demonstrate denial of service and buffer overrun vulnerabilities in Microsoft Works Spreadsheet (wksss.exe). Affected by the denial of service condition are Microsoft Works versions 6.0 through 8.x, 4.x/2000, Works for Windows 3.0, Works for Windows 2.0, Works for DOS, Excel 4.0, and Lotus 1-2-3. Affected by the buffer overrun condition are Excel 97 through 2000 and Excel 5.0/95.
| | Author: | Benjamin Tobias Franz | | Related File: | msworks-bof.txt | | File Size: | 9325 | | Last Modified: | Jul 15 04:45:05 2006 |
| MD5 Checksum: | dc6943bbee581e97b1e33d4e6ed4e48e |
|
| /// File Name: |
mybb-sql-115.php.txt |
Description:
|
Remote 'CLIENT-IP' SQL injection / create new admin exploit for MyBulletinBoard (MyBB) versions 1.1.5 and below.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 8596 | | Last Modified: | Jul 15 05:17:05 2006 |
| MD5 Checksum: | 44586dbc23c1907b89808f334ff751d8 |
|
| /// File Name: |
adplugbof.c |
Description:
|
Proof of concept test exploit for AdPlug versions 2.0 and below (and CVS version 04 and below) which suffer from multiple heap and buffer overflows.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | adplugbof.txt | | File Size: | 8254 | | Last Modified: | Jul 9 08:07:23 2006 |
| MD5 Checksum: | f09a7c940bd14eecdae78cfe2a639e17 |
|
| /// File Name: |
etomiteCMS-061-SQL.txt |
Description:
|
Etomite CMS versions 0.6.1 and below 'username' SQL injection and administrative credential disclosure exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 7566 | | Last Modified: | Jul 27 23:04:25 2006 |
| MD5 Checksum: | f18fa61d46a419eabaf89101a6f58998 |
|
| /// File Name: |
kailleraex.zip |
Description:
|
Test exploit for Kaillera versions 0.86 and below which suffer from a buffer overflow that can lead to arbitrary code execution.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | kailleraex.txt | | File Size: | 7528 | | Last Modified: | Jul 9 08:03:28 2006 |
| MD5 Checksum: | b81be16752eef0fdf513bbcabdd3e11e |
|
| /// File Name: |
pearl24.txt |
Description:
|
Pearl Products, such as the Pearl Forums version 2.4, Ngoc Biec version 1.4, Pearl For Biz version 2.4, and Pearl For Mambo version 1.6, all suffer from multiple remote file inclusion flaws.
| | Author: | Zero | | File Size: | 7362 | | Last Modified: | Jul 9 05:19:23 2006 |
| MD5 Checksum: | 9602cc1a81bd8c1177c81e235e0fd298 |
|
| /// File Name: |
horde3113010.txt |
Description:
|
Horde versions 3.1.1 and 3.0.10 suffer from multiple cross site scripting issues.
| | Author: | Moritz Naumann | | Homepage: | http://moritz-naumann.com/ | | File Size: | 6848 | | Last Modified: | Jul 9 07:36:44 2006 |
| MD5 Checksum: | 15309e9c4651faa6df24ff59aab19fe4 |
|
| /// File Name: |
CS-MARS_jboss-exploit.txt |
Description:
|
Cisco/Protego CS-MARS remote command execution and system compromise exploit that makes use of an insecure JBoss installation in CS-MARS versions below 4.2.1.
| | Author: | Jon Hart | | Related File: | cisco-sa-20060719-mars.txt | | File Size: | 6463 | | Last Modified: | Jul 24 00:06:19 2006 |
| MD5 Checksum: | 7edecad5a2bd49bd8c54fdf02e3676b1 |
|
| /// File Name: |
xss_research.htm |
Description:
|
This is a huge list of many popular web sites that are susceptible to cross site scripting attacks with links to examples.
| | Author: | SkyOut | | Homepage: | http://www.core-security.net | | File Size: | 6438 | | Last Modified: | Jul 20 05:54:50 2006 |
| MD5 Checksum: | 1eb959866a128b932ce5553aa0ba9941 |
|
| /// File Name: |
deluxeBB.txt |
Description:
|
DeluxeBB versions 1.07 and below suffer from multiple vulnerabilities including SQL injection and cross site scripting flaws.
| | Author: | Jessica Hope, Th3 M0ths | | File Size: | 5350 | | Last Modified: | Jul 20 05:01:53 2006 |
| MD5 Checksum: | c0d91ea3736b6d2fe1528264cab755c1 |
|
|
|
|
|