Section: .. / 0611-exploits /
| /// File Name: |
tikiwiki-1.9.5.txt |
Description:
|
tikiwiki version 1.9.5 suffers from a security vulnerability that allows anyone to dump the mysql user and password by creating a mysql error with the "sort_mode" variable.
| | Author: | securfrog | | File Size: | 1351 | | Last Modified: | Nov 2 19:46:20 2006 |
| MD5 Checksum: | 93024e281c3146d00bf9e44181442f96 |
|
| /// File Name: |
debug217_php.txt |
Description:
|
Invision Power Board 2.1.7 debug mode proof of concept exploit. Works if "Debug Level" is set to 3 or Enable SQL Debug Mode is turned on.
| | Author: | Rapigator | | File Size: | 3275 | | Last Modified: | Nov 2 19:43:52 2006 |
| MD5 Checksum: | b3b5ba445fb8bbe566765130aca1725c |
|
| /// File Name: |
phpMyConferences-8.0.2-2.txt |
Description:
|
phpMyConferences versions 8.0.2 and prior suffer from remote file inclusion in library.inc.php.
| | Author: | mfp.c | | File Size: | 662 | | Last Modified: | Nov 1 17:47:29 2006 |
| MD5 Checksum: | 34d14420c1fc2d68dc381454946de182 |
|
| /// File Name: |
BytesFall-exp.txt |
Description:
|
BytesFall Explorer suffers from an input sanitization vulnerability in login/doLogin.php which can lead to SQL injection. POC included that resets the admin password.
| | Author: | RedTeam Pentesting | | Homepage: | http://www.redteam-pentesting.de | | File Size: | 3438 | | Last Modified: | Nov 1 17:45:19 2006 |
| MD5 Checksum: | 3a4ad2fdc37704e9a590d3cdb1f816ed |
|
| /// File Name: |
SystemMessenger_xss.txt |
Description:
|
Sun java System Messenger Express suffers from a cross site scripting vulnerability in the errorHTML function.
| | Author: | Handrix | | Homepage: | http://www.morx.org | | File Size: | 2246 | | Last Modified: | Nov 1 17:38:45 2006 |
| MD5 Checksum: | d59b918d8d38ed06c147da8c55a0f88e |
|
| /// File Name: |
Bcwb2.5.txt |
Description:
|
Bcwb 2.5 suffers from multiple remote file inclusion vulnerabilities.
| | Author: | firewall1954 | | File Size: | 977 | | Last Modified: | Nov 1 17:28:35 2006 |
| MD5 Checksum: | 266a4dcf48dab05febd9fa18f0e6ca73 |
|
| /// File Name: |
nst-29.txt |
Description:
|
The Journal module in PHP-Nuke 7.9 and prior suffers from SQL injection in search.php. POC exploit included that grabs the password hash of the first admin.
| | Author: | [NST] | | Homepage: | http://www.neosecurityteam.net/ | | File Size: | 12842 | | Last Modified: | Oct 31 18:34:23 2006 |
| MD5 Checksum: | 93c7fef47bb65bcdc704a49530dd541c |
|
|
|
|
|