Section: .. / 0703-exploits /
| /// File Name: |
assetman24-lfi.txt |
Description:
|
AssetMan version 2.4a suffers from a local file disclosure vulnerability.
| | Author: | BorN To K!LL | | File Size: | 932 | | Last Modified: | Mar 13 21:18:58 2007 |
| MD5 Checksum: | f4ee51ef7a944b6317ed9db89bf3ac60 |
|
| /// File Name: |
asterisk-Invite.txt |
Description:
|
Proof of concept denial of service exploit for the Asterisk PBX that is susceptible to a remote denial of service vulnerability via a specially crafted INVITE message. Affected versions include 1.2.14, 1.2.15, 1.2.16, 1.4.1, and possibly earlier versions.
| | Author: | Radu State, Humberto J. Abdelnur, Olivier Festor | | File Size: | 1158 | | Last Modified: | Mar 26 22:22:09 2007 |
| MD5 Checksum: | eb08101e49a7f01a1c8ed41340647a1a |
|
| /// File Name: |
asterisk-sip-kill.c |
Description:
|
Remote denial of service exploit for Asterisk PBX that makes use of a bug in the SIP channel driver. Versions below 1.2.16 and below 1.4.1 are affected.
| | Author: | Anonymous | | File Size: | 2817 | | Last Modified: | Mar 8 17:42:48 2007 |
| MD5 Checksum: | 7bc997a83ca3b9c66f2f973b835daed5 |
|
| /// File Name: |
atr-sql.txt |
Description:
|
Active Trade version 2 suffers from a SQL injection vulnerability in default.asp.
| | Author: | CyberGhost | | Homepage: | http://aspspider.org/cgsecurity | | File Size: | 625 | | Last Modified: | Mar 23 20:54:04 2007 |
| MD5 Checksum: | e5fbab1ba69d8d812a1430046e5a295b |
|
| /// File Name: |
awebnews-rfi.txt |
Description:
|
aWebNews version 1.1 suffers from a remote file inclusion vulnerability.
| | Author: | ThE dE@Th | | File Size: | 857 | | Last Modified: | Mar 6 01:24:10 2007 |
| MD5 Checksum: | e0a9d4a78894b3470214cd6a54c0d1cf |
|
| /// File Name: |
bj-xss.txt |
Description:
|
BJ Webring suffers from a cross site scripting flaw.
| | Author: | sn0oPy | | File Size: | 372 | | Last Modified: | Mar 8 17:37:14 2007 |
| MD5 Checksum: | b2bf61a76f253dc9651d72ba528f4b2d |
|
| /// File Name: |
blogentry-xss.txt |
Description:
|
Blog-Entry suffers from multiple cross site scripting vulnerabilities.
| | Author: | Hanno Boeck | | Homepage: | http://www.hboeck.de/ | | File Size: | 1286 | | Last Modified: | Apr 2 18:26:51 2007 |
| MD5 Checksum: | 6689b002c77f49aee2a3c185af8f63b7 |
|
| /// File Name: |
BTP00001P005CF.zip |
Description:
|
Proof of concept exploit for Comodo Firewall Pro. Comodo Firewall Pro (former Comodo Personal Firewall) stores some of its internal settings in the registry key HKLM\SYSTEM\Software\Comodo\Personal Firewall. This key is protected by Comodo drivers such that other applications are not able to change the settings. This protection can be bypassed if very special conditions are met.
| | Homepage: | http://www.matousec.com/ | | Related File: | comodo-bypass.txt | | File Size: | 7577 | | Last Modified: | Mar 6 00:23:55 2007 |
| MD5 Checksum: | c0c0d78228e1b55c482155fe750e5f2b |
|
| /// File Name: |
BTP00012P002NF.zip |
Description:
|
Proof of concept exploit that demonstrates how Norton insufficiently protects its driver \Device\SymEvent against manipulation.
| | Homepage: | http://www.matousec.com/ | | Related File: | Norton-symtdi.txt | | File Size: | 3655 | | Last Modified: | Mar 20 00:53:25 2007 |
| MD5 Checksum: | 33aa94922de497dc63585160afb6e8e2 |
|
| /// File Name: |
built2go-xss.txt |
Description:
|
Built2Go version 1.0 suffers from cross site scripting vulnerabilities.
| | Author: | the_Edit0r | | File Size: | 1310 | | Last Modified: | Mar 6 01:25:16 2007 |
| MD5 Checksum: | b9f44dfdc746f792ead1109294056a33 |
|
| /// File Name: |
caid-msgeng.txt |
Description:
|
CA BrightStor ARCserve remote stack overflow exploit that takes advantage of msgeng.exe.
| | Author: | Winny Thomas | | File Size: | 6766 | | Last Modified: | Mar 19 23:59:23 2007 |
| MD5 Checksum: | 1388521454aee2669c9a327a37223708 |
|
| /// File Name: |
ccc20-xss.txt |
Description:
|
CoCounter version 2.0 suffers from a cross site scripting vulnerability.
| | Author: | Crackers_Child | | File Size: | 525 | | Last Modified: | Mar 26 22:26:43 2007 |
| MD5 Checksum: | f47f82b0043340311168a7a3b84ed7e9 |
|
| /// File Name: |
classweb-rfi.txt |
Description:
|
ClassWeb version 2.0.3 suffers from remote file inclusion vulnerabilities.
| | Author: | GolD_M | | Homepage: | http://www.tryag.cc/ | | File Size: | 347 | | Last Modified: | Mar 23 20:44:10 2007 |
| MD5 Checksum: | db2784d53cd960121db98b9507481898 |
|
| /// File Name: |
clbox-rfi.txt |
Description:
|
CLBOX version 1.0.1 suffers from a remote file inclusion vulnerability.
| | Author: | BorN To K!LL | | File Size: | 782 | | Last Modified: | Mar 20 11:09:12 2007 |
| MD5 Checksum: | 069fc061a3803025f5cabacf46c4c511 |
|
| /// File Name: |
clipshare-rfi.txt |
Description:
|
A remote file inclusion vulnerability exists in ClipShare version 1.5.3.
| | Author: | Hasadya Raed | | File Size: | 816 | | Last Modified: | Mar 13 21:09:43 2007 |
| MD5 Checksum: | 05367d1dc7ac867e07172b32de3d6777 |
|
| /// File Name: |
copperminepg-rfi.txt |
Description:
|
Coppermine Photo Gallery suffers from some remote file inclusion vulnerabilities.
| | Author: | Hasadya Raed | | File Size: | 931 | | Last Modified: | Mar 13 18:39:57 2007 |
| MD5 Checksum: | 1d1b7ded143dc8d26ae6e764d99ae3da |
|
| /// File Name: |
CORE-2007-0219.txt |
Description:
|
Core Security Technologies Advisory - The OpenBSD kernel contains a memory corruption vulnerability in the code that handles IPv6 packets. Exploitation of this vulnerability can result in remote execution of arbitrary code at the kernel level on the vulnerable systems and/or a remote denial of service condition. Affected systems include OpenBSD 4.1 prior to Feb. 26th, 2006, OpenBSD 4.0 Current, OpenBSD 4.0 Stable, OpenBSD 3.9, OpenBSD 3.8, OpenBSD 3.6, and OpenBSD 3.1. Proof of concept exploit included.
| | Author: | Alfredo Ortega, Mario Vilas, Gerardo Richarte | | Homepage: | http://www.coresecurity.com/corelabs/ | | File Size: | 18563 | | Related CVE(s): | CVE-2007-1365 | | Last Modified: | Mar 13 22:56:29 2007 |
| MD5 Checksum: | f37a6332b213078f5620d3413f0db749 |
|
| /// File Name: |
cpg-rfi.txt |
Description:
|
A remote file inclusion vulnerability exists in Coppermine Photo Gallery.
| | Author: | Hasadya Raed | | File Size: | 870 | | Last Modified: | Mar 23 21:49:39 2007 |
| MD5 Checksum: | 09dfdbc3259713f5ad66fcbdb21b6a17 |
|
| /// File Name: |
csa-driver.txt |
Description:
|
COMPASS SECURITY ADVISORY - The Linux drivers for the Omnikey CardMan 4040 smartcard reader contains a buffer overflow vulnerability. Local attackers with direct or indirect write permissions to a cmx device file can execute arbitrary code with kernel privileges or may cause a denial of service condition. Proof of concept exploit included.
| | Author: | Daniel Roethlisberger | | Homepage: | http://www.csnc.ch/ | | File Size: | 4704 | | Related CVE(s): | CVE-2007-0005 | | Last Modified: | Mar 13 18:26:05 2007 |
| MD5 Checksum: | 7dca159ebdcc3579a8aef062fa5d499b |
|
| /// File Name: |
datadomain-exec.txt |
Description:
|
DataDomain OS versions 3.0.0 through 4.0.3.5 suffer from an arbitrary command execution flaw.
| | Author: | Elliot Kendall | | File Size: | 2046 | | Last Modified: | Mar 29 03:02:36 2007 |
| MD5 Checksum: | 9c945837875c5605ea9373d740e29293 |
|
| /// File Name: |
dbimage-rfi.txt |
Description:
|
DBImageGallery version 1.2.2 suffers from remote file inclusion vulnerabilities.
| | Author: | Hasadya Raed | | File Size: | 1410 | | Last Modified: | Mar 6 02:33:45 2007 |
| MD5 Checksum: | b7ffe3d09b3c6fd0e6fd07047944bdbe |
|
| /// File Name: |
devcode.txt |
Description:
|
Exploit for the Microsoft Windows .ANI LoadAniIcon stack overflow vulnerability.
| | Author: | devcode29 | | File Size: | 4639 | | Related CVE(s): | CVE-2007-1765 | | Last Modified: | Apr 2 18:42:17 2007 |
| MD5 Checksum: | 7bb08f8016e7355ebe1fe858be809c5b |
|
| /// File Name: |
deviantART-xss.txt |
Description:
|
deviantART suffers from a cross site scripting vulnerability.
| | Author: | Raed | | File Size: | 570 | | Last Modified: | Mar 13 18:30:14 2007 |
| MD5 Checksum: | 7c272a8857658bbdd73a04a191251ec0 |
|
| /// File Name: |
dnsfun.c |
Description:
|
Exploiting Microsoft DNS dynamic updates for fun and profit.
| | Author: | Andres Tarasco | | Homepage: | http://www.514.es/ | | File Size: | 15378 | | Last Modified: | Mar 23 21:16:31 2007 |
| MD5 Checksum: | 6c4af2bef05d82e19d8cb3a3912fd004 |
|
| /// File Name: |
dproxy-v1.c |
Description:
|
Remote exploit for dproxy versions 0.5 and below. Binds a shell to TCP port 4444.
| | Author: | mu-b | | File Size: | 7068 | | Last Modified: | Apr 2 18:35:30 2007 |
| MD5 Checksum: | 52c1dcd14162b2cc97262976b36f2700 |
|
|
|
|
|