Section: .. / 0801-exploits /
| /// File Name: |
waraxe-2008-SA065.txt |
Description:
|
Coppermine version 1.4.14 suffers from a remote shell command execution vulnerability in include/imageObjectIM.class.php.
| | Author: | Janek Vind aka waraxe | | Homepage: | http://www.waraxe.us/ | | File Size: | 4715 | | Last Modified: | Jan 30 19:19:53 2008 |
| MD5 Checksum: | 9c55fa89b5c8cee7d6f0ad76e37797ef |
|
| /// File Name: |
auracms-exec.txt |
Description:
|
AuraCMS version 1.62 remote code execution exploit that makes use of stat.php.
| | Author: | k1tk4t | | Homepage: | http://newhack.org/ | | File Size: | 4706 | | Last Modified: | Jan 18 04:29:54 2008 |
| MD5 Checksum: | 9423f819b3ceefe1488484a92c7d86b3 |
|
| /// File Name: |
docebo-exec.txt |
Description:
|
Docebo versions 3.5.0.3 and below command execution exploit that makes use of lib.regset.php.
| | Author: | EgiX | | File Size: | 4688 | | Last Modified: | Jan 10 03:34:59 2008 |
| MD5 Checksum: | 1cdbe2343ef0f75ecc0b82e8aa16725a |
|
| /// File Name: |
pixelpost-sql.txt |
Description:
|
PixelPost 1.7 remote blind SQL injection exploit that makes use of the Content-Length header.
| | Author: | Silentz | | Homepage: | http://www.w4ck1ng.com/ | | File Size: | 4598 | | Last Modified: | Jan 16 23:57:37 2008 |
| MD5 Checksum: | 48080eca3033ed47e6ab8f2318a4a92e |
|
| /// File Name: |
docebo-sql.txt |
Description:
|
Docebo versions 3.5.02 and below SQL injection exploit that makes use of lib.regset.php.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 4554 | | Last Modified: | Jan 11 13:31:07 2008 |
| MD5 Checksum: | c662a66d86f6e0a1ec8c413772eccd25 |
|
| /// File Name: |
alitalk-multi.txt |
Description:
|
ALITALK version 1.9.1.1 suffers from severe remote SQL injection vulnerabilities.
| | Author: | tomplixsee | | File Size: | 4525 | | Last Modified: | Jan 16 23:55:49 2008 |
| MD5 Checksum: | 5bb7248777544f0cff8035d5ee8fbb18 |
|
| /// File Name: |
sami-overflow.txt |
Description:
|
Microsoft DirectX SAMI file parsing remote stack overflow exploit that binds a shell to port 4444.
| | Author: | Matteo Memelli | | Homepage: | http://be4mind.com/ | | File Size: | 4246 | | Last Modified: | Jan 9 01:40:02 2008 |
| MD5 Checksum: | 868705bc90701375ac09387da9a96f8a |
|
| /// File Name: |
digitalhive-sql.txt |
Description:
|
DigitalHive versions 2.0 RC2 and below remote SQL injection exploit.
| | Author: | j0j0 | | File Size: | 4182 | | Last Modified: | Jan 11 13:10:22 2008 |
| MD5 Checksum: | 525b21c2074db9c590ff049286dcbbe2 |
|
| /// File Name: |
cpg-sql.txt |
Description:
|
Coppermine Photo Gallery version 1.4.10 remote SQL injection exploit.
| | Author: | bazik | | File Size: | 4062 | | Last Modified: | Jan 21 20:43:53 2008 |
| MD5 Checksum: | 49628db9b7e97b43bdc1ad6c19b9e050 |
|
| /// File Name: |
TISA2008-01.txt |
Description:
|
Team Intell Security Advisory TISA2008-01 - The Linksys WRT54 GL suffers from an authentication bypass flaw via a cross site request forgery vulnerability.
| | Author: | Maldin d.o.o | | Homepage: | http://www.teamintell.com/ | | File Size: | 3902 | | Last Modified: | Jan 7 14:23:33 2008 |
| MD5 Checksum: | 9f561c253ba2d390a495ec2bc45f2c83 |
|
| /// File Name: |
rtssentry-overflow.txt |
Description:
|
RTS Sentry Digital Surveillance buffer overflow exploit that makes use of CamPanel.dll version 2.1.0.2.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 3886 | | Last Modified: | Jan 16 00:31:37 2008 |
| MD5 Checksum: | 685635d822b87a4ae1e5bdf34ce6ecb1 |
|
| /// File Name: |
sinecms-lfiexec.txt |
Description:
|
Sine CMS versions 2.3.5 and below suffer from local file inclusion and remote code execution vulnerabilities.
| | Author: | KiNgOfThEwOrLd | | Homepage: | http://www.inj3ct-it.org/ | | File Size: | 3875 | | Last Modified: | Jan 6 20:02:32 2008 |
| MD5 Checksum: | 43b9f3ac5db76bec5996ddf8b5452482 |
|
| /// File Name: |
zerocms-sql.txt |
Description:
|
Zero CMS versions 1.0 Alpha and below suffer from arbitrary upload and remote SQL injection vulnerabilities.
| | Author: | KiNgOfThEwOrLd | | Homepage: | http://www.inj3ct-it.org/ | | File Size: | 3841 | | Last Modified: | Jan 8 12:11:00 2008 |
| MD5 Checksum: | f800577c4ce58c64da79f108ee81bff0 |
|
| /// File Name: |
ddc-overflow.txt |
Description:
|
Digital Data Communications RtspVaPgCtrl Class remote buffer overflow exploit that makes use of RtspVapgDecoder.dll version 1.1.0.29.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 3821 | | Last Modified: | Jan 18 04:47:53 2008 |
| MD5 Checksum: | 6a0a8b13d29b2e96b334b84fbcb83b9c |
|
| /// File Name: |
26211-jumbodos.txt |
Description:
|
Linux Kernel versions 2.6.20 through 2.6.21.1 IPv6 Jumbo bug remote denial of service exploit.
| | Author: | Clemens Kurtenbach | | File Size: | 3793 | | Last Modified: | Jan 11 13:01:48 2008 |
| MD5 Checksum: | 9cda55eac812ffe42a21c8dc1b7c550a |
|
| /// File Name: |
mssln-overflow.txt |
Description:
|
Microsoft Visual InterDev version 6.0 (SP6) .sln file local buffer overflow exploit.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 3673 | | Last Modified: | Jan 11 13:04:24 2008 |
| MD5 Checksum: | 2b11c6304769ca07eadbf7f815d6f06c |
|
| /// File Name: |
DSECRG-08-003.txt |
Description:
|
Blogcms version 4.2.1b suffers from SQL injection and cross site scripting vulnerabilities.
| | Author: | Sh2kerr, Stas Svistunovich | | Homepage: | http://www.dsec.ru/ | | File Size: | 3660 | | Last Modified: | Jan 17 00:19:57 2008 |
| MD5 Checksum: | 195261491e46e14fbbd48b0c2b63df83 |
|
| /// File Name: |
ipb217-xsssql.txt |
Description:
|
Invision Power Board version 2.1.7 suffers from cross site scripting and SQL injection vulnerabilities.
| | Author: | Eugene Minaev | | Homepage: | http://itdefence.ru/ | | File Size: | 3650 | | Last Modified: | Jan 5 19:04:50 2008 |
| MD5 Checksum: | b051ffe4f645813a3cd7b46c26fcfd97 |
|
| /// File Name: |
upload-change.txt |
Description:
|
UploadImage version 1.0 and UploadScript version 1.0 remote change admin password exploit.
| | Author: | Dj7xpl | | Homepage: | http://nobody.ir/ | | File Size: | 3579 | | Last Modified: | Jan 10 03:23:56 2008 |
| MD5 Checksum: | 0c5379460f2d8c589a3fd0ddb8622b18 |
|
| /// File Name: |
igaming-sql.txt |
Description:
|
iGaming CMS versions 1.3.1 and below remote SQL injection exploit that makes use of archive.php.
| | Author: | Eugene Minaev, gemaglabin | | Homepage: | http://itdefence.ru/ | | File Size: | 3531 | | Last Modified: | Jan 11 13:06:46 2008 |
| MD5 Checksum: | ba53e18cd56ef329e9b9b761abec3d1d |
|
|
|
|
|