Packet Storm new exploits for March, 2007.
d5213326823b6600e93657539427681eAardvark Topsites PHP 5 suffers from a remote file inclusion vulnerability.
b4122d9a574af5bcca4b29e4b3853dc6Shop-SCRIPT FREE suffers from remote file inclusion vulnerabilities.
a3caa1620b94d53965ff7edda0af51c0SLAED_CMS_2 suffers from a remote file inclusion vulnerability.
7c2d8555b428b7d6ddfe8f331c58902dThe PHP-Fusion Calendar_Panel module suffers from a remote SQL injection vulnerability in show_event.php.
5f95af930c27dac3b82f063ca8367c85Exploit for the Microsoft Windows .ANI LoadAniIcon stack overflow vulnerability.
7bb08f8016e7355ebe1fe858be809c5bRemote exploit for dproxy versions 0.5 and below. Binds a shell to TCP port 4444.
52c1dcd14162b2cc97262976b36f2700Blog-Entry suffers from multiple cross site scripting vulnerabilities.
6689b002c77f49aee2a3c185af8f63b7Time-Assistant versions 6.2 and below suffer from a remote file inclusion vulnerability.
fe12846c2ca614269315d1d1cc1d0e71DrakeCMS suffers from a cross site scripting vulnerability in ui.dta.php.
66a72b4f845ba3184ff86d9068910ec2MyBB suffers from a change password vulnerability.
5bfaff25882035091a22070b75e179e3DataDomain OS versions 3.0.0 through 4.0.3.5 suffer from an arbitrary command execution flaw.
9c945837875c5605ea9373d740e29293Corel Worperfect X3 version 13.0.0.565 suffers from a stack overflow vulnerability. Exploit included.
8cece6f324de927d4cdfd1da2451acc5HP JetDirect print servers suffers from a remote denial of service flaw.
0d35f082f181f32b807931a800f07f59aBitWhizzy suffers from local file traversal and cross site scripting vulnerabilities.
64483de368bae49e63bad2e87378063aMonth of PHP Bugs - PHP version 4.4.5 and 4.4.6 session_decode() double free proof of concept exploit.
ac64d9748ea8b560e47f968fba2f7558The Linux kernel suffers from a DCCP memory disclosure vulnerability. This is the second proof of concept exploit related to this vulnerability. Kernel versions 2.6.20 and above are affected.
5a4c8586a8f76cfb8fd8494244694c0dThis Metasploit module exploits a stack overflow in the NaviCopa HTTP server 2.01 (release version 6th October 2006 or earlier). It is not the same vulnerability as the one described in BID 20250.
9af13150313142d7bbfee995b5be0c75Oracle 10g KUPM$MCP.MAIN SQL injection exploit version 1.
2a8a0eec2a5ea3879a641b43d8d6fbbeOracle 10g KUPM$MCP.MAIN SQL injection exploit version 2.
3c82a6a31634f209db1f378f07bb02acThe Linux kernel suffers from a DCCP memory disclosure vulnerability. Proof of concept exploit included. Kernel versions 2.6.20 and above are affected.
0a85b24758c65f57b208b459d9d1215aFlexBB version 1.0.0 10005 Beta Release 1 suffers from a SQL injection vulnerability when parsing the user supplied cookie value.
3d55dac35b5fdff4341cec44eab21230Xoops blind SQL injection exploit for print.php. Currently affects all versions.
66ec680fd32bc0067496746440e31e8aC-Arbre versions 0.6PR7 and below suffer from a remote file inclusion vulnerability.
cbf44d2d3cdd34f17aa4dc23178a958arealGuestbook_V5 suffers from a HTML injection vulnerability.
36992e869809a12a3a00804ff3eaffce