Section: .. / 0707-exploits /
| /// File Name: |
mozillaprotocolabuse.zip |
Description:
|
The Mozilla application platform currently has an unpatched input validation flaw which allows you to specify arbitrary command line arguments to any registered URL protocol handler process. Thunderbird version 2.0.0.5 fixes this. Full exploits included.
| | Author: | Thor Larholm | | Homepage: | http://larholm.com/ | | File Size: | 49162 | | Last Modified: | Jul 26 01:23:47 2007 |
| MD5 Checksum: | 1eb5ac7bc33d9647cfbf1967c41b6c50 |
|
| /// File Name: |
esri-overflow.txt |
Description:
|
ESRI ArcSDE version 9.0 through 9.2sp1 remote buffer overflow exploit.
| | Author: | Heretic2 | | File Size: | 26527 | | Last Modified: | Jul 6 23:33:46 2007 |
| MD5 Checksum: | b9e77931f9ce0e636782a2e784b6d2f3 |
|
| /// File Name: |
mkportal-sql.txt |
Description:
|
MkPortal versions 1.1.1 and below reviews and gallery modules remote SQL injection exploit.
| | Author: | Coloss | | File Size: | 15552 | | Last Modified: | Jul 12 21:18:30 2007 |
| MD5 Checksum: | 8233791dd419fca874f2fb34976bc283 |
|
| /// File Name: |
sapdb-seh.txt |
Description:
|
AP DB version 7.4 WebTools remote SEH overwrite exploit.
| | Author: | Heretic2 | | File Size: | 14630 | | Last Modified: | Jul 9 23:48:08 2007 |
| MD5 Checksum: | 5ac2f86c38b1831d73391ef5596ffe63 |
|
| /// File Name: |
corehttp-overflow.txt |
Description:
|
corehttp version 0.5.3alpha remote buffer overflow exploit.
| | Author: | vade79 | | Homepage: | http://fakehalo.us/ | | File Size: | 13539 | | Last Modified: | Jul 31 00:16:53 2007 |
| MD5 Checksum: | f94cd9f83f91db05428a8f172d80259f |
|
| /// File Name: |
0x82-apache-mod_jk.c |
Description:
|
Apache Tomcat Connector mod_jk version 1.2.19 remote buffer overflow exploit for Fedora Core 5,6 (exec-shield).
| | Author: | Xpl017Elz | | Homepage: | http://x82.inetcop.org | | File Size: | 11609 | | Last Modified: | Jul 9 20:57:37 2007 |
| MD5 Checksum: | 7237019e79ecd2b7a54187bb77cd1af4 |
|
| /// File Name: |
vivvocms-sql.txt |
Description:
|
Vivvo CMS versions 3.4 and below remote blind SQL injection exploit that makes use of index.php.
| | Author: | ajann | | File Size: | 10625 | | Last Modified: | Jul 19 00:15:26 2007 |
| MD5 Checksum: | 2660905f777e3fa82f3e0bee7d57dcab |
|
| /// File Name: |
netflow-xss.txt |
Description:
|
The NetFlow Analyzer version 5 and the OpManager version 7 suffer from cross site scripting vulnerabilities.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 10529 | | Last Modified: | Jul 7 00:26:29 2007 |
| MD5 Checksum: | ca73d8db88c2e0c22a0e76be0bfc735f |
|
| /// File Name: |
npfxpl.c |
Description:
|
WinPcap NPF.SYS privilege escalation vulnerability proof of concept exploit. Affects WinPcap versions 3.1 and 4.1.
| | Author: | Mario Ballano Bárcena | | Homepage: | http://www.48Bits.com | | File Size: | 8901 | | Last Modified: | Jul 11 02:48:15 2007 |
| MD5 Checksum: | 89f8a6fe5ec476acd50bb64d6ded3a10 |
|
| /// File Name: |
neotracepro-overflow.txt |
Description:
|
NeoTracePro version 3.25 ActiveC TraceTarger() remote buffer overflow exploit.
| | Author: | nitr0us | | File Size: | 8797 | | Last Modified: | Jul 9 23:49:29 2007 |
| MD5 Checksum: | 7f57760dceabbd9148169a95cd49100f |
|
| /// File Name: |
borland-overflow.txt |
Description:
|
Borland Interbase versions 2007 SP1 and below Create-Request remote overflow exploit that binds a shell to port 10282.
| | Author: | BackBone | | File Size: | 8448 | | Last Modified: | Jul 31 00:22:44 2007 |
| MD5 Checksum: | 6c6a94a1ade0bae420a437fdf27384b3 |
|
| /// File Name: |
lsa_transnames_heap-linux.rb.txt |
Description:
|
This Metasploit module triggers a heap overflow in the LSA RPC service of the Samba daemon. This module uses the TALLOC chunk overwrite method (credit Ramon and Adriano), which only works with Samba versions 3.0.21 through 3.0.24. Additionally, this module will not work when the Samba "log level" parameter is higher than "2". Linux version.
| | Author: | Ramon de Carvalho Valle, Adriano Lima, H D Moore | | Homepage: | http://www.risesecurity.org/ | | File Size: | 8017 | | Related CVE(s): | CVE-2007-2446 | | Last Modified: | Jul 26 02:00:21 2007 |
| MD5 Checksum: | 4f3d9021ab7aeab8ee51f9ee5605ad0c |
|
| /// File Name: |
pnphpbb2view-sql.txt |
Description:
|
PNphpBB2 versions 1.2i and below remote SQL injection exploit that makes use of viewforum.php.
| | Author: | Coloss | | File Size: | 7885 | | Last Modified: | Jul 6 23:39:17 2007 |
| MD5 Checksum: | 599095a3b3fff637ac31d1dc297f19b8 |
|
| /// File Name: |
asteridex-exec.txt |
Description:
|
AsteriDex versions 3.0 and below suffer from a remote code execution vulnerability in callboth.php. Full exploit provided.
| | Author: | Carl Livitt | | File Size: | 7370 | | Last Modified: | Jul 7 00:43:54 2007 |
| MD5 Checksum: | 915358aa10025749c70a6cf272551172 |
|
| /// File Name: |
lotus-overflow.txt |
Description:
|
Lotus Domino IMAP4 server version 6.5.4 / Windows 2000 Advanced Server x86 remote buffer overflow exploit.
| | Author: | Dominic Chell, prdelka | | File Size: | 7038 | | Last Modified: | Jul 20 22:30:19 2007 |
| MD5 Checksum: | c034bc24a2ccbd22b9171961180e067a |
|
| /// File Name: |
linpha131-sql.txt |
Description:
|
LinPHA versions 1.3.1 and below remote blind SQL injection exploit that makes use of new_images.php.
| | Author: | EgiX | | File Size: | 6506 | | Last Modified: | Jul 31 00:15:12 2007 |
| MD5 Checksum: | d3838baf9474200047b3e0e616b2e435 |
|
| /// File Name: |
alstrasoft-multi.txt |
Description:
|
A number of cross site scripting and SQL injection vulnerabilities affect various products from AlstraSoft including Video Share Enterprise, Text Ads Enterprise, SMS Text Messaging Enterprise, Affiliate Network Pro, Article Manager Pro, and AskMe Pro.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 6292 | | Last Modified: | Jul 23 00:35:41 2007 |
| MD5 Checksum: | 924c4b376a0b4c9d2efc4ca72db635e3 |
|
| /// File Name: |
exploit.c |
Description:
|
Remote buffer overflow exploit for Windows RSHD version 1.7.
| | Author: | Joey Mengele | | File Size: | 5953 | | Last Modified: | Jul 25 00:08:06 2007 |
| MD5 Checksum: | 3a98f11d51a929b4b32871c0db6efb77 |
|
| /// File Name: |
ipswitch-overflow.txt |
Description:
|
IPSwitch IMail server 2006 SEARCH remote stack overflow exploit. Binds a shell to port 1154.
| | Author: | ZhenHan.Liu | | Homepage: | http://www.ph4nt0m.org/ | | File Size: | 5764 | | Last Modified: | Jul 26 01:04:01 2007 |
| MD5 Checksum: | 5aec044f25a17b719729eb54cd242c04 |
|
| /// File Name: |
lsa_transnames_heap-solaris.rb.txt |
Description:
|
This Metasploit module triggers a heap overflow in the LSA RPC service of the Samba daemon. This module uses the TALLOC chunk overwrite method (credit Ramon and Adriano), which only works with Samba versions 3.0.21 through 3.0.24. Additionally, this module will not work when the Samba "log level" parameter is higher than "2". Solaris version.
| | Author: | Ramon de Carvalho Valle, Adriano Lima, H D Moore | | Homepage: | http://www.risesecurity.org/ | | File Size: | 5515 | | Related CVE(s): | CVE-2007-2446 | | Last Modified: | Jul 26 02:04:19 2007 |
| MD5 Checksum: | 9f07c9cd8fd013c9608f103024c1c839 |
|
| /// File Name: |
jnlp-overflow.txt |
Description:
|
Sun Java WebStart JNLP stack buffer overflow denial of service exploit.
| | Author: | ZhenHan.Liu | | Homepage: | http://www.ph4nt0m.org/ | | File Size: | 5338 | | Last Modified: | Jul 11 02:17:50 2007 |
| MD5 Checksum: | 40de6e961aa501015d4647780efe3a7e |
|
|
|
|
|