you are connected

Recent Files

Files RSS Feed
Mandriva Linux Security Advisory 2012-016
Posted Feb 11, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-016 - A File Inclusion vulnerability was discovered and corrected in GLPI. This advisory provides the latest version of GLPI that is not vulnerable to this issue.

tags | advisory, file inclusion
systems | linux, mandriva
OnxShop CMS 1.5.0 Cross Site Scripting
Posted Feb 11, 2012
Authored by Benjamin Kunz Mejri | Site vulnerability-lab.com

OnxShop CMS version 1.5.0 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
Microsoft Security Bulletin Advance Notification For February 2012
Posted Feb 11, 2012
Site microsoft.com

This is an advance notification of 9 security bulletins that Microsoft is intending to release on February 14, 2012.

tags | advisory
CubeCart 3.0.20 Open Redirection
Posted Feb 11, 2012
Authored by Aung Khant | Site yehg.net

CubeCart versions 3.0.20 and below suffer from an open URL redirection vulnerability.

tags | exploit
D-Link DAP 1150 CSRF / XSS / Denial Of Service
Posted Feb 11, 2012
Authored by MustLive

The D-Link DAP 1150 suffers from cross site request forgery, cross site scripting and denial of service vulnerabilities.

tags | exploit, denial of service, vulnerability, xss, info disclosure, csrf
Zen-Cart 1.3.9h Cross Site Request Forgery
Posted Feb 11, 2012
Authored by DisK0nn3cT

Zen-Cart version 1.3.9h suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
Astaro Security Gateway Whitelist Bypass
Posted Feb 11, 2012
Authored by Timeless Prototype

The Astaro Security Gateway suffers from a whitelist bypass vulnerability due to a poorly formed regex.

tags | exploit, bypass
Dolibarr CMS 3.2.0 Alpha SQL Injection
Posted Feb 11, 2012
Authored by Benjamin Kunz Mejri, longrifle0x | Site vulnerability-lab.com

Dolibarr CMS version 3.2.0 Alpha suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
Dolibarr CMS 3.2.0 Alpha Local File Inclusion
Posted Feb 11, 2012
Authored by Benjamin Kunz Mejri, longrifle0x | Site vulnerability-lab.com

Dolibarr CMS version 3.2.0 Alpha suffers from multiple local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, file inclusion
Pfile 1.02 Cross Site Scripting / SQL Injection
Posted Feb 11, 2012
Authored by indoushka

Pfile version 1.02 suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
Nova CMS Remote File Inclusion
Posted Feb 11, 2012
Authored by indoushka

Nova CMS suffers from multiple remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, code execution, file inclusion
OpenSSH 5.9p1 Backdoor
Posted Feb 11, 2012
Authored by IPSECS

This is a patch for OpenSSH version 5.9p1 that adds a magic root password backdoor, logs usernames and passwords and keeps connections from being logged in wtmp, utmp, etc.

tags | root, encryption
systems | unix
Kloxo LxCenter Server CP 6.1.10 Cross Site Scripting
Posted Feb 11, 2012
Site vulnerability-lab.com

Kloxo LxCenter Server CP version 6.1.10 suffers from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss
STHS v2 Web Portal 2.2 SQL Injection
Posted Feb 11, 2012
Authored by Liyan Oz

STHS v2 Web Portal version 2.2 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, web, sql injection
MachForm 2.4 Remote File Inclusion
Posted Feb 11, 2012
Authored by indoushka

MachForm version 2.4 suffers from multiple remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, code execution, file inclusion
BASE 1.4.5 Remote File Inclusion / Shell Creation
Posted Feb 11, 2012
Authored by indoushka

BASE version 1.4.5 suffers from multiple remote file inclusion vulnerabilities and a shell creation vulnerability.

tags | exploit, remote, shell, vulnerability, code execution, file inclusion
Gocart 1.0.2 Remote File Inclusion
Posted Feb 11, 2012
Authored by indoushka

Gocart version 1.0.2 suffers from multiple remote file inclusion vulnerabilities.

tags | exploit, remote, vulnerability, code execution, file inclusion
Indianapolis Superbowl 2012 SQL Injection
Posted Feb 11, 2012
Authored by Alexander Fuchs | Site vulnerability-lab.com

The Indianapolis Superbowl 2012 website suffered from multiple remote SQL injection vulnerabilities.

tags | advisory, remote, vulnerability, sql injection
GLPI 0.80.61 Local File Inclusion / Remote File Inclusion
Posted Feb 11, 2012
Authored by Emilien Girault

GLPI versions 0.80.61 and below suffer from local file inclusion and remote file inclusion vulnerabilities.

tags | exploit, remote, local, vulnerability, code execution, file inclusion
BeWelcome Cross Site Scripting
Posted Feb 11, 2012
Authored by Sony

BeWelcome suffers from a cross site scripting vulnerability.

tags | exploit, xss
DotDotPwn - The Directory Traversal Fuzzer 3.0
Posted Feb 11, 2012
Authored by nitr0us, chr1x

DotDotPwn is a very flexible intelligent fuzzer to discover directory traversal vulnerabilities in software such as Web/FTP/TFTP servers, Web platforms such as CMSs, ERPs,Blogs, etc. Also, it has a protocol-independent module to send the desired payload to the host and port specified. On the other hand, it also could be used in a scripting way using the STDOUT module.

Changes: Multiple new switches and encodings added.
tags | web, vulnerability, protocol, fuzzer
systems | unix
Citrix Provisioning Services 5.6 SP1 Streamprocess Opcode 0x40020000 Buffer Overflow
Posted Feb 10, 2012
Authored by AbdulAziz Hariri | Site metasploit.com

This Metasploit module exploits a remote buffer overflow in the Citrix Provisioning Services 5.6 SP1 (without Hotfix CPVS56SP1E043) by sending a malformed packet to the 6905/UDP port. The module has been successfully tested on Windows Server 2003 SP2, Windows 7, and Windows XP SP3.

tags | exploit, remote, overflow, udp
systems | windows, xp, 7
Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow
Posted Feb 10, 2012
Authored by Abysssec, sinn3r, Alexander Gavrun | Site metasploit.com

This Metasploit module exploits a vulnerability found in Adobe Flash Player's Flash10u.ocx component. When processing a MP4 file (specifically the Sequence Parameter Set), Flash will see if pic_order_cnt_type is equal to 1, which sets the num_ref_frames_in_pic_order_cnt_cycle field, and then blindly copies data in offset_for_ref_frame on the stack, which allows arbitrary remote code execution under the context of the user. Numerous reports also indicate that this vulnerability has been exploited in the wild. Please note that the exploit requires a SWF media player in order to trigger the bug, which currently isn't included in the framework. However, software such as Longtail SWF Player is free for non-commercial use, and is easily obtainable.

tags | exploit, remote, arbitrary, code execution
NIELD (Network Interface Events Logging Daemon) 0.22
Posted Feb 10, 2012
Authored by t2mune | Site nield.sourceforge.net

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.

Changes: This release includes minor updates and bugfixes.
tags | kernel, system logging
systems | unix
SMW+ 1.5.6 Cross Site Scripting
Posted Feb 10, 2012
Authored by Sony

SMW+ version 1.5.6 suffers from a cross site scripting vulnerability.

tags | exploit, xss
View Older Files →

File Archive:

February 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    36 Files
  • 2
    Feb 2nd
    46 Files
  • 3
    Feb 3rd
    45 Files
  • 4
    Feb 4th
    27 Files
  • 5
    Feb 5th
    12 Files
  • 6
    Feb 6th
    26 Files
  • 7
    Feb 7th
    48 Files
  • 8
    Feb 8th
    54 Files
  • 9
    Feb 9th
    28 Files
  • 10
    Feb 10th
    50 Files
  • 11
    Feb 11th
    21 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

News Tags

packet storm

© 2012 Packet Storm. All rights reserved.

close