Remote exploit for Squid V2.4.DEVEL4 and below on linux/x86.
24d91d5829db84c6495bdd00d3c2d301Windows exploit for the SphereServer Ultima Online Roleplay Server v0.5x for Linux, FreeBSD, and Win32 which runs on tcp port 2593 and contains a denial of service vulnerability.
b5628022c968fa70d68b1676050034847350wurm is a linux/x86 wu_ftpd remote root exploit for the double free() bug affecting v2.4.2 to 2.6.1. This code was abandoned in a honey pot and is published under Fair Use Law 17 U.S.C.A 107
e004a15cec5f254723de055a9c1ae8b97350squish is a Linux / x86 Squid remote exploit. Tested against Debian Squid_2.3.4-2, squid_2.4.1-1, and squid_2.4.2. This code was abandoned in a honey pot and is published under Fair Use Law 17 U.S.C.A 107
dce9bab965424a0e8530f96a1894753bSolaris /bin/login remote root exploit for SPARC and x86. This code was abandoned in a honey pot and is published under Fair Use Law 17 U.S.C.A 107
be208b9e1dd0a6fba505c92d0945e63dPacket Storm new exploits for May, 2002.
ecbc62a22118d344f7108dd053dac2803CDaemon FTP Server v2.0 buffer overflow dos exploit.
e65fd71eb92068a7397b56ae8855aa34IIS 5.0 .asp buffer overrun remote exploit which runs cmd.exe. The .asp overflow is documented in ms02-018.
39f8b5fbccb0aa6f4d417bbb98827c9fImap4 prior to v2001a remote exploit for Linux. Requires user account, includes offsets for Slackware 7.1 and Redhat 7.2.
9e109c1318dce5900a74e98a0079f70aWarFTPd v1.65 for Win2k remote buffer overflow exploit in win32 perl. Included shellcode pops up a message box.
2f1e9c047c0f8fbc01c0fa7aaf0705c7Local exploit for the Sendmail 8.12.3 and below flock denial of service vulnerability.
7cee23161ef73a980d225d0f55c73258NewAtlanta ServletExec ISAPI v4.1 contains three vulnerabilities. Remote users can read any file in the webroot, crash the server, and display the physical path of the web root. Patch available here.
f082e55bfd5b5972b2fd9e2bf27cbdfcIE 6sp1 for Windows 2000 and 98 has bugs in the showModalDialog and showModelessDialog methods of displaying dialog boxes which can be used to execute arbitrary commands. Most unpatched IE and Outook installations are vulnerable. Online demonstration exploit MS02-023, but IE 5.5 and 5.0 are still vulnerable.
0b3468fe4df00c7606a7d7ecba08faf7NMRC Advisory #21 - The inJoin Directory Server v4.0 for Solaris 2.8 has a vulnerability in the iCon admin interface listening on tcp port 1500 which allows an attacker with the correct username and password to read any file accessible to the ids user. Exploit URLs included. Fix available here.
c23bd9955e8f621398dc807e1743baa4WolfMail.cgi, a script that works similarly to formmail.cgi, allows users to send mail via a web interface. The configuration for WolfMail.cgi is not internally hardcoded but is passed via parameters in html input statements allowing any user to send fake mail.
4dc284e013f1ea74e1cf545eaf08b528Remote FreeBSD cURL exploit for versions 6.1 - 7.3. More info available here.
4049de1a59e4a9420e508eaab09daeb4Remote linux cURL exploit for versions 6.1 - 7.3. More info available here.
6f87b51db3d1aed1909d7807b92ba901Local root exploit for OpenBSD up to 3.1 which takes advantage of the fd race and skeyaudit binary.
71e8d4f9d9897554f0d7ad1d4e8f096fAOL Instant Messenger (AIM) contains a buffer overflow in the code that is responsible for parsing requests to run external applications. The overflow can be used to remotely penetrate a system and it is not possible to block these requests in the AIM client. No client side fix is currently available.
07123bd01c6abc79b2eef9d8b71c4a4eIIS 5.0 .asp buffer overrun remote exploit which runs cmd.exe. The .asp overflow is documented in ms02-018.
22d1af31c0c413e763b4bfabde7430e0