Section: .. / 0512-exploits /
| /// File Name: |
mIRCexploitXPSP2eng.c |
Description:
|
mIRC exploit for versions 6.16 and below. Proof of concept exploit that does not actually increase privileges but could be useful in restricted environments.
| | Author: | Jordi Corrales | | File Size: | 7749 | | Last Modified: | Dec 28 17:23:55 2005 |
| MD5 Checksum: | f42e9afc57363d0249b6b3aa0790d5ed |
|
| /// File Name: |
mkportalXSS.txt |
Description:
|
MkPortal with smf forum is susceptible to a cross site scripting flaw.
| | Author: | spyMASter | | Homepage: | http://www.cyber-warrior.org | | File Size: | 508 | | Last Modified: | Dec 14 02:07:06 2005 |
| MD5 Checksum: | 5977b955d1a3623fe302409883dcd8eb |
|
| /// File Name: |
MS05-053.c |
Description:
|
Microsoft Windows Metafile (WMF) remote exploit which takes advantage of the bug known as ms05-053. This program creates a special .wmf file which crashes IE by overflowing the "mtNoObjects" header.
| | Author: | Winny Thomas | | File Size: | 4821 | | Last Modified: | Dec 14 05:12:31 2005 |
| MD5 Checksum: | 380f01f84a68f99123f0eaeefe547cc1 |
|
| /// File Name: |
muts_mailenable_imap_examine.pm.txt |
Description:
|
Metasploit exploit for a remote buffer overflow that exists in the MailEnable Enterprise 1.1 IMAP EXAMINE command. This vulnerability affects MailEnable Enterprise 1.1 without the ME-10009.EXE patch.
| | Author: | Mati Aharoni | | Related File: | mailenable11.txt | | File Size: | 3621 | | Last Modified: | Dec 28 00:11:51 2005 |
| MD5 Checksum: | 0759dc48707c12312cfe8713c81d9517 |
|
| /// File Name: |
nodez.txt |
Description:
|
Nodez version 4.6.1.1 is susceptible to multiple cross site scripting flaws.
| | Author: | X1ngBox | | File Size: | 684 | | Last Modified: | Dec 13 23:41:34 2005 |
| MD5 Checksum: | 82a3c5d82fb2dc7b094bdd6c7e7c0b3a |
|
| /// File Name: |
openview_connectednodes_exec.pm.txt |
Description:
|
This Metasploit module exploits an arbitrary command execution vulnerability in the HP OpenView connectedNodes.ovpl CGI application. The results of the command will not be displayed to the screen.
| | Author: | Valerio Tesei | | File Size: | 2731 | | Related OSVDB(s): | 19057 | | Related CVE(s): | CVE-2005-2773 | | Last Modified: | Dec 14 03:26:31 2005 |
| MD5 Checksum: | ae5ae0d62af26ea683bce8a720fc56eb |
|
| /// File Name: |
oracle9i_xdb_http.pm.txt |
Description:
|
This Metasploit module exploits a stack overflow in the authorization code of the Oracle 9i HTTP XDB service.
| | Author: | y0 | | File Size: | 4118 | | Last Modified: | Dec 14 03:23:36 2005 |
| MD5 Checksum: | 3904180db4222415f801532251f226a4 |
|
| /// File Name: |
perl-cal-29920.txt |
Description:
|
Perl-Cal version 2.99.20, the CGI script written by Acme Software, is susceptible to cross site scripting.
| | Author: | Sumit Siddharth | | File Size: | 3690 | | Last Modified: | Dec 14 00:00:06 2005 |
| MD5 Checksum: | b903eca64d8af5272644b0927b77790d |
|
| /// File Name: |
PHPGedView.php.txt |
Description:
|
PHPGedView versions less than or equal to 3.3.7 arbitrary local and remote code execution and php injection exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 15014 | | Last Modified: | Dec 28 15:40:01 2005 |
| MD5 Checksum: | 1c536361235cf3a330b3e3b7f98d107f |
|
| /// File Name: |
phpMyAdminSQL.txt |
Description:
|
phpMyAdmin version 2.7.0 is susceptible to SQL injection attacks via the server_privileges.php script. Details provided.
| | Author: | Alice Bryson | | File Size: | 1798 | | Last Modified: | Dec 27 03:20:32 2005 |
| MD5 Checksum: | 16bc082433656f2e812665cc5bc17ad0 |
|
| /// File Name: |
phpMyChat0146.txt |
Description:
|
phpMyChat version 0.14.6 is susceptible to cross site scripting flaws in start_page.css.php, style.css.php, and users_popupL.php.
| | Author: | Louis Wang | | Homepage: | http://www.fortinet.com/ | | File Size: | 1630 | | Last Modified: | Dec 3 00:38:22 2005 |
| MD5 Checksum: | aca7825d44871757fae3eb67dd784b18 |
|
| /// File Name: |
playsmsXSS.txt |
Description:
|
PlaySMS is susceptible to cross site scripting attacks.
| | Author: | mohajali2k4 | | File Size: | 213 | | Last Modified: | Dec 27 03:21:26 2005 |
| MD5 Checksum: | 5771d887aad81790eb546ae09bbfb7b2 |
|
| /// File Name: |
SEC-20051211-0.txt |
Description:
|
SEC-CONSULT Security Advisory 20051211-0 - Horde versions 3.0.7 and below, Kronolith versions 2.0.5 and below, Mnemo version 2.0.2 and below, Nag versions 2.0.3 and below, and Turba versions 2.0.4 and below are susceptible to cross site scripting attacks.
| | Author: | Johannes Greil | | Homepage: | http://www.sec-consult.com | | File Size: | 8439 | | Last Modified: | Dec 14 02:16:06 2005 |
| MD5 Checksum: | cd3e50c6d30cf26aab9c6ebd6280f69c |
|
| /// File Name: |
SMF11SQL.txt |
Description:
|
Simple Machines Forum version 1.1 rc1 is susceptible to SQL injection attacks.
| | Author: | trueend5 | | Homepage: | http://www.KAPDA.ir | | File Size: | 2037 | | Last Modified: | Dec 14 01:18:45 2005 |
| MD5 Checksum: | d419208a5047a55cc6a819f041e3c940 |
|
| /// File Name: |
sugar_suite_40beta.txt |
Description:
|
SugarSuite Open Source versions 4.0beta and below suffer from remote code execution and file inclusion flaws. Exploit provided.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 10408 | | Last Modified: | Dec 13 23:19:41 2005 |
| MD5 Checksum: | ff2fa3cc8d3377e7cc559a9c0fb94fc3 |
|
| /// File Name: |
ThWboard.txt |
Description:
|
ThWboard version 3 beta 2.8 is susceptible to HTML injection, cross site scripting, and SQL injection attacks. Details provided.
| | Author: | trueend5 | | Homepage: | http://kapda.ir/ | | File Size: | 2349 | | Last Modified: | Dec 13 23:22:53 2005 |
| MD5 Checksum: | 83304c54e2bbb7b0fe3c031772285bab |
|
|
|
|
|