Section:  .. / 0912-exploits  /

Page 4 of 25
<< 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 >> Files 75 - 100 of 600
Currently sorted by: File SizeSort By: File Name, Last Modified

 ///  File Name: ministreampls-overflow.txt
Description:
Mini-Stream buffer overflow exploit that creates a malicious .pls file.
Author:Ron Henry
File Size:3799
Last Modified:Dec 30 13:48:14 2009
MD5 Checksum:27362dafe809508461dec89807bfee40

 ///  File Name: cybsec-ossimupload.txt
Description:
OSSIM version 2.1.5 suffers from an arbitrary file upload vulnerability.
Author:Nahuel Grisolia
Homepage:http://www.cybsec.com/
File Size:3798
Last Modified:Dec 16 18:52:11 2009
MD5 Checksum:fe8f28b6da9c82774f5a656caad72e15

 ///  File Name: theeta-sqlxss.txt
Description:
Theeta CMS suffers from cross site scripting and SQL injection vulnerabilities.
Author:c0dy
Homepage:http://r00tDefaced.net/
File Size:3793
Last Modified:Dec 1 18:00:51 2009
MD5 Checksum:ac1c235e72c2ff508921e7685f7efd8d

 ///  File Name: ciscoasa-bypass.txt
Description:
Cisco VPN SSL Clientless lets administrators define rules to specific targets within the private network that WebVPN users will be able to access. This specific targets are published using links in VPN SSL home page. These links (URL) are protected (obfuscated) using a ROT13 substitution and converting ASCII characters to hexadecimal. An user with a valid account and without "URL entry" can access any internal/external resource simply taken an URL, encrypt with ROT 13, convert ASCII characters to hexadecimal and appending this string to Cisco VPN SSL URL. Brilliant. Versions 8.x and below are affected. Proof of concept included.
Author:David Eduardo Acosta Rodriguez
File Size:3776
Last Modified:Dec 17 17:23:06 2009
MD5 Checksum:23532263eadd9395718b1e4e0b9dda08

 ///  File Name: servu_session_cookie.rb.txt
Description:
This Metasploit module exploits a buffer overflow in Rhinosoft Serv-U 9.0.0.5. Sending a specially crafted POST request with an overly long session cookie string, an attacker may be able to execute arbitrary code.
Author:Megumi Yanagishita,Nikolas Rangos,jduck
Homepage:http://www.metasploit.com
File Size:3743
Related OSVDB(s):59772
Last Modified:Dec 30 22:09:18 2009
MD5 Checksum:931db12c36feeb70bd316fc1a6bf706d

 ///  File Name: disa-exec.txt
Description:
Running DISA SRR scripts against your server can get you easily rooted. They run arbitrary binaries discovered on the filesystem as root. They apparently need another Security Readiness Review script to first audit their own Security Readiness Review scripts.
Author:Frank Stuart
File Size:3687
Last Modified:Dec 3 15:52:30 2009
MD5 Checksum:6804e5afa5f3bcd948fdea58acf48ae6

 ///  File Name: horde-xss.txt
Description:
Horde version 3.3.5 suffers from a cross site scripting vulnerability.
Author:Juan Galiana Lara
File Size:3659
Related CVE(s):CVE-2009-3701
Last Modified:Dec 17 17:46:27 2009
MD5 Checksum:0eb18415e3871a404efcf7e1f1825217

 ///  File Name: wbb3-sql.txt
Description:
Remote blind SQL injection exploit for Wbb3.
Author:Molli
File Size:3638
Last Modified:Dec 29 19:06:49 2009
MD5 Checksum:a98db81f343c422fa4ffe40fd8dbeecd

 ///  File Name: altn_securitygateway.rb.txt
Description:
Alt-N SecurityGateway is prone to a buffer overflow condition. This is due to insufficient bounds checking on the "username" parameter. Successful exploitation could result in code execution with SYSTEM level privileges. NOTE: This service doesn't restart, you'll only get one shot. However, it often survives a successful exploitation attempt.
Author:jduck
Homepage:http://www.metasploit.com
File Size:3634
Related OSVDB(s):45854
Related CVE(s):CVE-2008-4193
Last Modified:Dec 30 22:10:58 2009
MD5 Checksum:ddc08f6e706c6e3e358cd1bf8d367ec0

 ///  File Name: simplephpblog-lfi.txt
Description:
Simple PHP Blog versions 0.5.1 and below suffer from a local file inclusion vulnerability.
Author:Juan Galiana Lara
File Size:3617
Last Modified:Dec 18 16:45:35 2009
MD5 Checksum:3c34a75a92fa98ffdf7bda878822bd8e

 ///  File Name: piwigo-sqlxss.txt
Description:
Piwigo version 2.0.6 suffers from remote SQL injection, cross site request forgery and cross site scripting vulnerabilities.
Author:mr_me
File Size:3594
Last Modified:Dec 13 18:54:49 2009
MD5 Checksum:49b0dff7196b42451685777cb9787cd2

 ///  File Name: nctaudiofile2_setformatlikesample.r..>
Description:
This Metasploit module exploits a stack overflow in the NCTAudioFile2.Audio ActiveX Control provided by various audio applications. By sending a overly long string to the "SetFormatLikeSample()" method, an attacker may be able to execute arbitrary code.
Author:MC,dookie,jduck
Homepage:http://www.metasploit.com
File Size:3585
Related OSVDB(s):32032
Related CVE(s):CVE-2007-0018
Last Modified:Dec 30 22:13:50 2009
MD5 Checksum:14e3c6dc8363e6a58fe53cc396099750

 ///  File Name: oscommerce_filemanager.rb.txt
Description:
osCommerce is a popular open source E-Commerce application. The admin console contains a file management utility that allows administrators to upload, download, and edit files. This could be abused to allow unauthenticated attackers to execute arbitrary code with the permissions of the webserver.
Author:egypt
Homepage:http://www.metasploit.com
File Size:3577
Related OSVDB(s):60018
Last Modified:Dec 30 20:15:02 2009
MD5 Checksum:3182e31e7b732ee6b1a9fd7995c97684

 ///  File Name: phpyellow-shell.txt
Description:
phpYellow suffers from a remote shell upload vulnerability.
Author:indoushka
File Size:3576
Last Modified:Dec 31 21:27:33 2009
MD5 Checksum:a9f9935a38d7c971c7de35e0a82b1541

 ///  File Name: ubbthreads-rfi.txt
Description:
UBB.Threads version 6 suffers from remote file inclusion vulnerabilities.
Author:indoushka
File Size:3565
Last Modified:Dec 30 18:32:03 2009
MD5 Checksum:e396b743da59c1a162f6900977487ad0

 ///  File Name: erm-overflow.txt
Description:
Easy RM to MP3 version 2.7.3.700 buffer overflow exploit that creates a malicious .m3u file.
Author:Ron Henry
File Size:3528
Last Modified:Dec 29 15:53:00 2009
MD5 Checksum:2d84718df17c37a20dd04d0ad84fb521

 ///  File Name: zencart-disclose.txt
Description:
Zen Cart suffers from a remote file disclosure vulnerability.
Author:Bogdan Calin
Homepage:http://www.acunetix.com/
File Size:3500
Last Modified:Dec 10 11:02:47 2009
MD5 Checksum:e9e121b7ad63c5563fa4b24443c97c50

 ///  File Name: ermtm-overflow.txt
Description:
Easy RM to MP3 version 2.7.3.700 buffer overflow exploit that creates a malicious .m3u file.
Author:bibi-info
File Size:3469
Last Modified:Dec 29 15:55:36 2009
MD5 Checksum:a983fbdc7789ecfcae589118ceea4ed8

 ///  File Name: phpbb_highlight.rb.txt
Description:
This Metasploit module exploits two arbitrary PHP code execution flaws in the phpBB forum system. The problem is that the 'highlight' parameter in the 'viewtopic.php' script is not verified properly and will allow an attacker to inject arbitrary code via preg_replace().
Author:H D Moore,Patrick Webster,Val Smith
Homepage:http://www.metasploit.com
File Size:3453
Related OSVDB(s):11719,17613
Related CVE(s):CVE-2005-2086, CVE-2004-1315
Last Modified:Dec 30 20:16:11 2009
MD5 Checksum:218c8dd71901742151b5c25c52885e4e

 ///  File Name: elkagroupv-sql.txt
Description:
Software from Elkagroup appears to suffer from a remote SQL injection vulnerability.
Author:SadHaCkEr
Homepage:http://www.tryag.cc/
File Size:3427
Last Modified:Dec 7 17:41:43 2009
MD5 Checksum:2f34e0bfd66bcc42607308ae5c7f2471

 ///  File Name: livehelp-xss.txt
Description:
Live Help version 2.6.0 Final suffers from a cross site scripting vulnerability.
Author:indoushka
File Size:3423
Last Modified:Dec 31 20:57:44 2009
MD5 Checksum:e2d728f601a4e27a06607b12b7d655de

 ///  File Name: ezcart-xsrf.txt
Description:
Ez Cart version 1.0 suffers from multiple cross site request forgery vulnerabilities.
Author:Milos Zivanovic
File Size:3415
Last Modified:Dec 15 17:04:29 2009
MD5 Checksum:e08252774a7adf7ac41965d5edbf5de1

 ///  File Name: castripper-overflow.txt
Description:
CastRipper buffer overflow exploit that creates a malicious .m3u file.
Author:bibi-info
File Size:3383
Last Modified:Dec 29 19:00:19 2009
MD5 Checksum:50dfe02b23d031956c4fd32163d1cfb1

 ///  File Name: fastfind-xss.txt
Description:
FastFind version 2005.0.3 suffers from a cross site scripting vulnerability.
Author:indoushka
File Size:3378
Last Modified:Dec 31 21:05:41 2009
MD5 Checksum:733a0f2357fdc0856f45cecdf9fc54b5

 ///  File Name: phpmycart-xssbypass.txt
Description:
PHPMyCart version 1.3 suffers from cross site scripting and bypass vulnerabilities.
Author:indoushka
File Size:3367
Last Modified:Dec 31 21:28:42 2009
MD5 Checksum:1afe7a3176993b7508b8fdced544ce74