Packet Storm new exploits for August, 2004.
e3ace716b8302d22fb2b673989fa063aRemote exploit that will change an IP address for the D-Link DCS-900 IP camera, due to the fact that it listens for a 62976/udp broadcast packet telling it what IP address to use without any authentication.
cda6badab6d0afdafacc7b3bff56b715Remote exploit for Citadel/UX versions 6.23 and below that makes use of the USER directive overflow. Successful exploitation adds an account in /etc/passwd.
20fc661867702ea3aa6a9c1ade96752bProof of concept exploit that makes use of a denial of service vulnerability in Ground Control II: Operation Exodus versions 1.0.0.7 and below.
a9f5b15d52ca8d7951bf47812a819cc8Keene Digital Media Server version 1.0.2 is susceptible to a directory traversal attack due to a lack of sufficient input validation.
8a2171fc611f46b35b2c5ec61ae7895aExploit that simulates POP3 server which sends a specially crafted email to a vulnerable Gaucho email client, triggering an overflow and binding a shell on port 2001. Version 1.4 build 145 is susceptible.
c4c57886b7699669cec7822a1aa61409Exploit that was found in the wild by k-otik.com that makes use of the Winamp vulnerability where insufficient restrictions on Winamp skin zip files (.wsz) allow a malicious attacker to place and execute arbitrary programs on a victim's system.
fb35990d5bd2f87809064c4d26d7a472Poor variable sanitization in Google's GMail system allows users to surf anonymously.
bd4339b67925bd9102e5324c16010ecfNetworkEverywhere router Model NR041 suffers a script injection over DHCP vulnerability. Full exploitation provided.
4e30ea5cc16c13a7d52355734ec9e5a1Test exploit for Painkiller versions 1.3.1 and below that makes use of a memory corruption flaw.
ae28b5004823fe6e14ce53b57a383cf1GulfTech Security Exploit - Easy File Sharing webserver version 1.25 denial of service exploit that consumes 99% of the CPU.
8a93ae7bc840615e0e2cbde7b9c5b413GulfTech Security Advisory - Easy File Sharing webserver version 1.25 is susceptible to denial of service and unauthorized system access vulnerabilities.
15b7fdb4a5b6ad2e27e5534508113c39WebAPP is susceptible to a directory traversal attack and another flaw that allows an attacker the ability to retrieve the DES encrypted password hash of the administrator.
d6c340b9a08828edc0ca782e1187cadeSquirrelmail chpasswd local root bruteforce exploit.
0ba65553e32acb0b39e0e99b0cfc8e50PHP based exploit for Gallery versions 1.4.4 and below that makes use of an arbitrary file upload flaw.
05693fb275ee8e9d64e65892054a950bHafiye 1.0 has a terminal escape sequence injection vulnerability that can result in a denial of service and remote root compromise. Exploit included.
ba176c1917a8df85b3c7f22bfd54e958MusicDaemon versions 0.0.3 and below suffer from a remote denial of service and flaw where /etc/shadow can be extracted. Exploit included.
d6c7ee7b0ef2783d63261d968b4b0338Axis versions 2100, 2110, 2120, 2420, and 2130 Network Camera along with the 2400 and 2401 Video Servers are susceptible to passwd file retrieval vulnerabilities, unauthenticated admin user additions, and hardcoded login/password flaws.
3e83d84a0274030f1df56173ebf03200Heap overflow exploit for the qt BMP parsing bug foundd in versions 3.3.2.
5e8e6c1e1eec51f034ae2b8459d28bb4MyDNS is susceptible to a SQL injection and directory traversal attack that allows for arbitrary file download. Version 1.4.2 fixes the SQL injection bug while the other bug is in all releases.
aec2e2241221fc1f8af47d957188900dGulfTech Security Advisory - BadBlue Webserver version 2.5 is susceptible to a denial of service attack when multiple connections are made to it from a single host. Exploit provided.
6e4e79c4f7dc7d86b591731ad5519977Local exploit for xv that makes use of the BMP parsing buffer overflow. Binds a shell to port 7000.
a68b2cc8dc45b9278a02169bd6afb026PHP based exploit for YaPiG 0.x that allows for an attacker to create arbitrary files on a vulnerable server.
3f8dea802eb03868e89ce6af0fd8bf18Merak Webmail server version 5.2.7 has cross site scripting, full path disclosure, exposure of PHP files, and SQL injection vulnerabilities.
d99db9f9afb9b41de3696570604d53afIpSwitch IMail Server versions 8.1 and below password decryption utility. This server uses the polyalphabetic Vegenere cipher to encrypt its user passwords. This encryption scheme is relatively easy to break.
354e62a6cba4b1329c0352f7595bb2dc