Packet Storm new exploits for April, 2007.
37263a0b4787bdfe4f3e8b41dc1e37a2RealPlayer 10 remote denial of service exploit that makes use of the .ra file flaw.
5a0b5afa6b3541d4543bef61069e92c83proxy version 0.5.3g proxy.c logurl() remote buffer overflow exploit for win32. Binds a shell to tcp port 7979.
6c25c781ca73d4e22164246425a480123proxy version 0.5.3g proxy.c logurl() remote buffer overflow exploit for Linux. Can spawn a bind shell or launch connect-back code.
4aa3b80e3126b2db928f68b83dd8fe4dFenice OMS server version 1.10 remote root buffer overflow exploit.
5332710197aa081c6d97686d14b3152dIPIX Image Well ActiveX buffer overflow exploit that executes calc.exe.
c39411b3574e4f123916fe6b7f8cffb3Internet Explorer NCTAudioFile2.AudioFile ActiveX remote stack overflow exploit.
833e6149a64cff02bc15c9f60a7c3355Winamp versions 5.34 and below .MP4 file code execution exploit that spawns calc.exe or binds a shell to tcp port 4444.
cd4e895cbb55416b3007794ed7cc36d7Photoshop CS2/CS3 and Paint Shop Pro version 11.20 .PNG buffer overflow exploit that spawns calc.exe or binds a shell to tcp port 4444.
fc0d9a02bd500a7cac2f3e3062315cdbIrfanView versions 4.00 and below .IFF buffer overflow exploit that spawns calc.exe or binds a shell to tcp port 4444.
edd9cda2a0ec61be978e6373dab4e70aGimp version 2.2.14 buffer overflow exploit that spawns calc.exe or binds a shell to tcp port 4444.
e99d279f20f1628d8c0de62e8bdef028FreshView version 7.15 buffer overflow exploit that spawns calc.exe or binds a shell to tcp port 4444.
4084865a59f45484cd88c31f44071fb5ABC-View Manager version 1.42 buffer overflow exploit that spawns calc.exe or binds a shell to tcp port 4444.
20e39970115fc134e1db7b32ea5bbd0aWordPress plugin wordTube versions 1.43 and below suffer from a remote file inclusion vulnerability.
ade67937e2f164bf0db1b9fe63a69e00WordPress plugin wp-Table versions 1.43 and below suffer from a remote file inclusion vulnerability.
5b5e9808a8a5719ca673615c956713f6psipuss version 1.0 remote change admin password exploit that makes use of editusers.php.
31d24efee88516aa07a5cb1e1d263f31The Merchant versions 2.2.0 and below suffer from a remote file inclusion vulnerability in index.php.
d7e6308564aee473b766ba867b452e2eImageview version 5.3 suffers from a local file inclusion vulnerability in fileview.php.
05069d7c9f85e6a5cf2d448ab014b2fbVP-ASP suffers from a SQL injection vulnerability. Details provided.
62abaf2555cb5ce6eb0e01fb2253fe5fRemote heap smash exploit for mydns versions 1.1.0 and below.
274b37368d8dc2f5b79d524cbae37f53TCExam versions 4.0.011 and below SessionUserLang shell injection exploit.
8e74bdcc62cc9a85847a82c17c2c4358The WordPress myGallery plugin versions 1.4b4 and below suffer from a remote file inclusion vulnerability.
5ce50606bb0a578877430883443889daThe PostNuke pnFlashGames module version 1.5 suffers from a remote SQL injection vulnerability.
55f0ff92cd5df0b42cbc7bf7102c2af1burnCMS versions 0.2 and below suffer from remote file inclusion vulnerabilities.
f47e172ac904be7b7ca0bd857799be49Firefly version 1.1.01 suffers from a remote file inclusion vulnerability.
06eff052032477f731bca869b1b2aa1e