Section: .. / 0711-exploits /
| /// File Name: |
viewpoint-overflow.txt |
Description:
|
Viewpoint Media Player version 3.2 for Internet Explorer remote stack overflow proof of concept exploit.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 4129 | | Last Modified: | Nov 6 22:27:03 2007 |
| MD5 Checksum: | a027a51b52adc2ef08ab786145da73d4 |
|
| /// File Name: |
cygwin-overflow.txt |
Description:
|
Cygwin is vulnerable to a buffer overflow when checking filename lengths. cygwin1.dll versions up to 1.5.7 are susceptible.
| | Author: | Jesus Olmos Gonzalez | | File Size: | 3872 | | Last Modified: | Nov 26 21:49:20 2007 |
| MD5 Checksum: | 20fb5ba384fafc5019b93acaf0190eb4 |
|
| /// File Name: |
seditio-sql.txt |
Description:
|
Seditio CMS versions 1.21 and below remote SQL injection exploit.
| | Author: | InATeam | | Homepage: | http://inattack.ru/ | | File Size: | 3497 | | Last Modified: | Nov 30 00:53:26 2007 |
| MD5 Checksum: | 468a077a42d53b68260892de589cbfce |
|
| /// File Name: |
SA-20071101-0.txt |
Description:
|
SEC Consult Security Advisory 20071101-0 - The SonicWALL SSL-VPN solution comes with various ActiveX Controls which allows users to access the VPN with Internet Explorer. These controls contain various vulnerabilities. Some details provided. Vulnerable versions include SonicWALL SSL-VPN 1.3.0.3, WebCacheCleaner ActiveX Control 1.3.0.3, and NeLaunchCtrl ActiveX Control 2.1.0.49.
| | Author: | Bernhard Mueller | | Homepage: | http://www.sec-consult.com/ | | File Size: | 3467 | | Last Modified: | Nov 1 12:40:39 2007 |
| MD5 Checksum: | 4d8c8385c3e51e858ef006e53fd8e09c |
|
| /// File Name: |
vtls-xss.txt |
Description:
|
VTLS Inc.'s vtls.web.gateway CGI is susceptible to a cross site scripting vulnerability. Versions up to 48.1.0 are affected.
| | Author: | Jesus Olmos Gonzalez | | File Size: | 3352 | | Last Modified: | Nov 13 12:40:04 2007 |
| MD5 Checksum: | 2a8b7b1bc67d3bbbf94037535e82cdfc |
|
| /// File Name: |
devmass-rfi.txt |
Description:
|
DevMass Shopping Cart versions 1.0 and below suffer from a remote file inclusion vulnerability.
| | Author: | S.W.A.T. | | Homepage: | http://www.xmors.com/ | | File Size: | 3212 | | Last Modified: | Nov 26 21:13:59 2007 |
| MD5 Checksum: | c99fcfeba52d250d10489b09a2acdea5 |
|
| /// File Name: |
sentineldetails-traverse.txt |
Description:
|
SafeNet Inc.'s Sentinel Protection Server and Sentinel Keys Server products include web servers which are vulnerable to directory traversal attacks. Full details provided.
| | Author: | Elliot Kendall | | File Size: | 3204 | | Last Modified: | Nov 26 22:53:21 2007 |
| MD5 Checksum: | d6ebdd5f7c5aa730f18575ceabf0543a |
|
| /// File Name: |
runcms-lfi.txt |
Description:
|
RunCMS versions 1.6 and below suffer from a local file inclusion vulnerability.
| | Author: | trueend5 | | Homepage: | http://www.kapda.ir/ | | File Size: | 3077 | | Last Modified: | Nov 26 21:53:15 2007 |
| MD5 Checksum: | 877a97e8d6dd5d91794c19bddff832a9 |
|
| /// File Name: |
sciuris-inject.txt |
Description:
|
Sciurus Hosting Panel remote code injection exploit.
| | Author: | Liz0ziM | | Homepage: | http://www.expw0rm.com/ | | File Size: | 2984 | | Last Modified: | Nov 26 16:33:18 2007 |
| MD5 Checksum: | e451e42019ef88a0c604bb61ffb032a0 |
|
| /// File Name: |
bcoos-lfisql.txt |
Description:
|
bcoos version 1.0.10 suffers from local file inclusion and SQL injection vulnerabilities.
| | Author: | trueend5 | | Homepage: | http://www.kapda.ir/ | | File Size: | 2954 | | Last Modified: | Nov 26 17:35:20 2007 |
| MD5 Checksum: | a8799da8a6452464a0e42945f675d93e |
|
| /// File Name: |
qt_public.tar.gz |
Description:
|
Apple QuickTime RTSP response Content-type remote stack rewrite exploit for Internet Explorer 6/7.
| | Author: | Yag Kohha | | Related Exploit: | aquick-universal.txt | | File Size: | 2884 | | Last Modified: | Nov 27 22:55:52 2007 |
| MD5 Checksum: | e6f416f2debf73019e613a9b48030d21 |
|
| /// File Name: |
foxnews-xss.txt |
Description:
|
FoxNews.com appears susceptible to a cross site scripting vulnerability.
| | Homepage: | http://xssworm.com/ | | File Size: | 2842 | | Last Modified: | Nov 12 20:23:28 2007 |
| MD5 Checksum: | 03383aa238f154460201150f41a9182c |
|
| /// File Name: |
vigilecms-multi.txt |
Description:
|
VigileCMS version 1.4 suffers from local file inclusion, cross site scripting, and cross site request forgery vulnerabilities.
| | Author: | DevilAuron | | Homepage: | http://devilsnight.altervista.org/ | | File Size: | 2790 | | Last Modified: | Nov 26 16:30:06 2007 |
| MD5 Checksum: | 05ff2ea389f5d3dbe3066636be2c2720 |
|
| /// File Name: |
skyportal-multi.txt |
Description:
|
SkyPortal version RC6 suffers from multiple SQL injection vulnerabilities along with an unauthorized access to messages flaw.
| | Homepage: | http://www.bugreport.ir/ | | File Size: | 2739 | | Last Modified: | Nov 26 17:37:48 2007 |
| MD5 Checksum: | b916ffb36caad8a8ac0a3170e14a8987 |
|
| /// File Name: |
wpquiz-sql.txt |
Description:
|
wpQuiz version 2.7 suffers from multiple remote SQL injection vulnerabilities.
| | Author: | Kacper | | Homepage: | http://devilteam.eu/ | | File Size: | 2680 | | Last Modified: | Nov 27 22:49:16 2007 |
| MD5 Checksum: | e8def58121202d2e6e3daf32b2bde72b |
|
| /// File Name: |
softbiz2-sql.txt |
Description:
|
Softbiz Ad Management Plus Script versions 1 suffers from a remote SQL injection vulnerability.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 2640 | | Last Modified: | Nov 12 19:46:34 2007 |
| MD5 Checksum: | b3b04d3277014787ed7ea29d329fffd8 |
|
| /// File Name: |
softbiz3-sql.txt |
Description:
|
Softbiz Banner Exchange Network Script version 1.0 suffers from a remote SQL injection vulnerability.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 2616 | | Last Modified: | Nov 12 19:47:20 2007 |
| MD5 Checksum: | a935ede6782ed189da979e4fe24b407e |
|
| /// File Name: |
syner-lfi.txt |
Description:
|
Synergiser versions 1.2 RC1 and below suffer from local file inclusion and full path disclosure vulnerabilities.
| | Author: | KiNgOfThEwOrLd | | Homepage: | http://www.inj3ct-it.org/ | | File Size: | 2611 | | Last Modified: | Nov 1 12:37:44 2007 |
| MD5 Checksum: | 5de83e685a1ff681bc49a850ddee626d |
|
| /// File Name: |
sfshoutbox-inject.txt |
Description:
|
SF-Shoutbox versions 1.2.1 through 1.4 suffer from HTML and Javascript injection vulnerabilities.
| | Author: | SkyOut | | Homepage: | http://www.core-security.net/ | | File Size: | 2574 | | Last Modified: | Nov 5 11:09:45 2007 |
| MD5 Checksum: | bfcacb79c443e24b5c9e65d1effd05ce |
|
| /// File Name: |
ucms-backdoor.txt |
Description:
|
Ucms version 1.4, 1.7, and 1.8 suffer from a backdoor vulnerability allowing for remote code execution.
| | Author: | D4m14n, shadowleet | | Homepage: | http://www.opencosmo.com/ | | File Size: | 2566 | | Last Modified: | Nov 26 18:05:06 2007 |
| MD5 Checksum: | 6a5aa795bdc40928324f9ff3666bcbb6 |
|
| /// File Name: |
phpnukema-sql.txt |
Description:
|
PHP-Nuke Module Advertising blind SQL injection exploit.
| | Author: | Guns | | Homepage: | http://www.0x90.com.ar/ | | File Size: | 2531 | | Last Modified: | Nov 12 22:13:06 2007 |
| MD5 Checksum: | 387e9b73cdd9dec64053915dd996ef01 |
|
| /// File Name: |
bcoos-sqlxss.txt |
Description:
|
bcoos versions 1.0.10 and below suffer from cross site scripting and SQL injection vulnerabilities.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 2522 | | Last Modified: | Nov 28 20:15:32 2007 |
| MD5 Checksum: | 051227c1abe093f587291db4854390ec |
|
| /// File Name: |
jbcexplorer-exec.txt |
Description:
|
JBC Explorer versions 7.20 RC 1 and below remote code execution exploit.
| | Author: | DarkFig | | File Size: | 2467 | | Last Modified: | Nov 5 11:43:43 2007 |
| MD5 Checksum: | d34a48a98e62646be49da372b4eb7c25 |
|
|
|
|
|