Section: .. / 0601-exploits /
| /// File Name: |
EV0021.txt |
Description:
|
Venom Board version 1.22 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1039 | | Last Modified: | Jan 10 05:58:19 2006 |
| MD5 Checksum: | 0595dd1c491f271032a218697aae24b9 |
|
| /// File Name: |
EV0022.txt |
Description:
|
MyPhPim version 01.05 is susceptible to cross site scripting and SQL injection vulnerabilities. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1201 | | Last Modified: | Jan 15 02:35:55 2006 |
| MD5 Checksum: | b65c15eaae35191db1b602732629f8b7 |
|
| /// File Name: |
EV0024.txt |
Description:
|
CaLogic Calendars version 1.2.2 is susceptible to cross site scripting attacks.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1070 | | Last Modified: | Jan 22 01:04:38 2006 |
| MD5 Checksum: | a34ce177aa9b5e8a5a00d098a66db7b2 |
|
| /// File Name: |
EV0026.txt |
Description:
|
TankLogger version 2.4 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1048 | | Last Modified: | Jan 15 17:34:48 2006 |
| MD5 Checksum: | 1a254764515ad09d8c965a402d714a6d |
|
| /// File Name: |
EV0027.txt |
Description:
|
Wordcircle version 2.17 is susceptible to SQL injection attacks that allows for authentication bypass. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 989 | | Last Modified: | Jan 15 17:35:41 2006 |
| MD5 Checksum: | 142aa49c577d9d8aa7f1872cd3e41d41 |
|
| /// File Name: |
EV0028.txt |
Description:
|
Wordcircle 2.17 is susceptible to SQL injection and cross site scripting flaws. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 974 | | Last Modified: | Jan 15 17:36:38 2006 |
| MD5 Checksum: | 3341e56cb78277d002f0d92594b54f6d |
|
| /// File Name: |
EV0029.txt |
Description:
|
Light Weight Calendar version 1.0 is susceptible to remote php code execution. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1071 | | Last Modified: | Jan 21 07:18:17 2006 |
| MD5 Checksum: | 3953cd22bff9935a5f9a96a0d6bc6969 |
|
| /// File Name: |
EV0030.txt |
Description:
|
Benders Calendar version 1.0 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 936 | | Last Modified: | Jan 21 21:59:22 2006 |
| MD5 Checksum: | 7ebb2ba13608faf7ca94d6dce5959253 |
|
| /// File Name: |
EV0031.txt |
Description:
|
Bit 5 Blog version 8.01 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1057 | | Last Modified: | Jan 21 22:07:49 2006 |
| MD5 Checksum: | 66d8fcf4a63578928449c544f89f0c8e |
|
| /// File Name: |
EV0032.txt |
Description:
|
Bit 5 Blog version 8.01 is susceptible to arbitrary javascript injection. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 925 | | Last Modified: | Jan 21 22:10:12 2006 |
| MD5 Checksum: | a664ffd29c32aaa80b641274f0f74ab8 |
|
| /// File Name: |
EXPL-A-2006-001.txt |
Description:
|
exploitlabs.com Advisory 047 - AspTopSites is susceptible to SQL injection attacks. Details on exploitation provided.
| | Author: | Donnie Werner | | Homepage: | http://exploitlabs.com | | File Size: | 1791 | | Last Modified: | Jan 11 07:11:06 2006 |
| MD5 Checksum: | f9c2e8e3609609e6f71aa5bf40246ae8 |
|
| /// File Name: |
ExpressionEngine-1.4.1.txt |
Description:
|
ExpressionEngine 1.4.1 does not sanatize the HTTP_REFERER variable. This can be used to post HTTP query with fake Referrer value which may contain arbitrary html or script code. This code will be executed when administrator(or any user) will open Referrer Statistics.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/vulns/48/summary.html | | File Size: | 1137 | | Last Modified: | Jan 26 11:16:04 2006 |
| MD5 Checksum: | de8a40d525006723af46d5ab925d4feb |
|
| /// File Name: |
eyeBeam_dos.c |
Description:
|
eyeBeam softphone remote denial of service SIP header mishandling exploit.
| | Author: | ZwelL | | File Size: | 3619 | | Last Modified: | Jan 22 00:42:15 2006 |
| MD5 Checksum: | 2d22cac710562f5f5ed1b16714e701f8 |
|
| /// File Name: |
EZDatabase.txt |
Description:
|
EZDatabase versions below 2.1.2 are susceptible to cross site scripting, directory traversal, and path disclosure flaws.
| | Author: | Josh Zlatin-Amishav | | File Size: | 906 | | Last Modified: | Jan 21 20:06:58 2006 |
| MD5 Checksum: | e1fb3cf01a1dcfc6a357961936e7690f |
|
| /// File Name: |
ezDatabase20.txt |
Description:
|
ezDatabase versions 2.0 and below are susceptible to remote php file inclusion flaws due to a lack of sanitizing variables.
| | Author: | Pridels Team | | Homepage: | http://pridels.blogspot.com | | File Size: | 1047 | | Last Modified: | Jan 15 18:19:30 2006 |
| MD5 Checksum: | b063abadc38f3993016c8b7fed112f70 |
|
| /// File Name: |
FogBugzXSS.txt |
Description:
|
FogBugz versions 4.029 and below suffer from a cross site scripting vulnerability.
| | Author: | M.Neset KABAKLI | | Homepage: | http://www.wakiza.com | | File Size: | 777 | | Last Modified: | Jan 15 16:43:32 2006 |
| MD5 Checksum: | e9d36d56dd105938d908819d49e29d11 |
|
| /// File Name: |
geoBlog-MOD_1.0.txt |
Description:
|
geoBlog MOD_1.0 suffers from an SQL injection vulnerability in the $tmpCategory variable.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/vulns/33/summary/bt/ | | File Size: | 1245 | | Last Modified: | Jan 26 06:20:04 2006 |
| MD5 Checksum: | 3747e3e14c10b3aeca505ddb2462b3c5 |
|
| /// File Name: |
geronimo_css.txt |
Description:
|
Apache Geronimo version 1.0 suffers from cross site scripting vulnerabilities.
| | Author: | Oliver Karow | | Homepage: | http://www.oliverkarow.de | | File Size: | 1361 | | Last Modified: | Jan 21 21:41:13 2006 |
| MD5 Checksum: | 246d64556b8377602e7647db2718be1c |
|
| /// File Name: |
HelmXSS.txt |
Description:
|
Helm version 3.2.8 is susceptible to cross site scripting attacks.
| | Author: | M.Neset KABAKLI | | Homepage: | http://www.wakiza.com | | File Size: | 925 | | Last Modified: | Jan 15 17:33:08 2006 |
| MD5 Checksum: | cfe94c7d04512524524ed95512c5ff82 |
|
| /// File Name: |
homeftp_v1.1_xpl.c |
Description:
|
HomeFTP versions 1.1 and below remote denial of service exploit.
| | Author: | Pi3cH, cvh | | Homepage: | http://www.kapda.ir/ | | File Size: | 3339 | | Last Modified: | Jan 15 18:21:14 2006 |
| MD5 Checksum: | 928270b4d741a17745a9f45166872e89 |
|
| /// File Name: |
hsphereXSS.txt |
Description:
|
H-Sphere versions 2.4.3 Patch 8 and below suffer from a cross site scripting vulnerability.
| | Author: | M.Neset KABAKLI | | Homepage: | http://www.wakiza.com | | File Size: | 1206 | | Last Modified: | Jan 15 17:03:42 2006 |
| MD5 Checksum: | 9bc330c668318d624534c154cf2552f5 |
|
| /// File Name: |
HYSA-2006-001.txt |
Description:
|
HYSA-2006-001 h4cky0u.org Advisory 010 - phpBB 2.0.19 search.php and profile.php DOS Vulnerability
| | Author: | h4cky0u | | Homepage: | http://www.h4cky0u.org | | File Size: | 15961 | | Last Modified: | Jan 26 11:11:07 2006 |
| MD5 Checksum: | 527fddee8232f657ffeeb1fe2176efe4 |
|
| /// File Name: |
HYSA-2006-002.txt |
Description:
|
HYSA-2006-002 h4cky0u.org Advisory 011 - Phpclanwebsite 1.23.1 Multiple Vulnerabilities
| | Author: | h4cky0u | | Homepage: | http://www.h4cky0u.org | | File Size: | 13081 | | Last Modified: | Jan 26 11:12:33 2006 |
| MD5 Checksum: | d7c03e183639aea5f891076876d4b1ea |
|
| /// File Name: |
icq-xss.txt |
Description:
|
An ICQ.com search script (search_result.php) is vulnerable to cross-site scripting attacks. An attacker can exploit the vulnerable script to have arbitrary script code executed in the browser of an authenticated ICQ user in the context of the ICQ webpage. resulting in the theft of cookie-based authentication giving the attacker temporary access to the victim's account, as well as other type of attacks.
| | Author: | _6mO_HaCk | | Homepage: | http://www.morx.org/iseekyowned.html | | File Size: | 2959 | | Last Modified: | Jan 25 08:37:37 2006 |
| MD5 Checksum: | 3b1bcaf74df52280df7119519cc15c27 |
|
|
|
|
|