Section: .. / 0802-exploits /
| /// File Name: |
yahoomusic-overflow4.txt |
Description:
|
Yahoo! Music Jukebox AddButton() ActiveX buffer overflow exploit.
| | Author: | Elazar Broad | | File Size: | 6811 | | Last Modified: | Feb 4 13:33:06 2008 |
| MD5 Checksum: | 471b8482045b453525a7934f34498c0b |
|
| /// File Name: |
move-overflow.txt |
Description:
|
Move Networks Quantum Streaming Player control buffer overflow exploit that makes use of UploadLogs() and spawns calc.exe or a shell on tcp/4444.
| | Author: | Elazar Broad | | File Size: | 6810 | | Last Modified: | Feb 26 18:08:02 2008 |
| MD5 Checksum: | 494f4767652244ffb26389822b200a82 |
|
| /// File Name: |
surgemailz.zip |
Description:
|
Proof of concept exploit for SurgeMail Mail Server version 38k4 and below and beta 39a along with Netwin's Webmail versions 3.1s and below which are all susceptible to format string and buffer overflow vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | surgemailz.txt | | File Size: | 6808 | | Last Modified: | Feb 25 16:14:09 2008 |
| MD5 Checksum: | 6a725af5114faff77684aa7b02d83032 |
|
| /// File Name: |
yahoomusic-overflow2.txt |
Description:
|
Yahoo! Music Jukebox MediaGrid AddBitmap() ActiveX buffer overflow exploit.
| | Author: | Elazar Broad | | File Size: | 6775 | | Last Modified: | Feb 4 13:27:14 2008 |
| MD5 Checksum: | 8f466e96859f852999815f7c0e9c8708 |
|
| /// File Name: |
rpmlpdbof.zip |
Description:
|
Exploit for the RPM Remote Print Manager versions 4.5.1.11 and below which suffer from a unicode related buffer overflow vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | rpmlpdbof.txt | | File Size: | 6745 | | Last Modified: | Feb 12 17:48:53 2008 |
| MD5 Checksum: | b250754bced7b65712d85f8a65b69e58 |
|
| /// File Name: |
imagestationsony-overflow.txt |
Description:
|
ImageStation ActiveX buffer overflow exploit that makes use of SonylSUpload.cab version 1.0.0.38 and can spawn calc.exe or bind a shell.
| | Author: | Elazar Broad | | File Size: | 6717 | | Last Modified: | Feb 11 15:51:50 2008 |
| MD5 Checksum: | a454ae1c00730c64fe88ecbedfc7dffa |
|
| /// File Name: |
cyanuro.zip |
Description:
|
Exploit for Opium OPI Server versions 4.10.1028 and below along with a large amount of cyanPrintIP products that suffer from a format string vulnerability in ReportSysLogEvent as well as a server crash flaw.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | cyanuro.txt | | File Size: | 6640 | | Last Modified: | Feb 11 16:42:21 2008 |
| MD5 Checksum: | ca307b5d4ba18cf433cd682a659a69b3 |
|
| /// File Name: |
philipsvoip-multi.txt |
Description:
|
The Philips VOIP841 DECT cordless phone with an embedded Skype client suffers from a hidden administrative interface with a default login, directory traversal, and cross site scripting vulnerabilities.
| | Author: | Luca Carettoni | | Homepage: | http://www.securenetwork.it/ | | File Size: | 6615 | | Last Modified: | Feb 14 18:13:24 2008 |
| MD5 Checksum: | a3d7eab1ce5c455c869a8cc9e3a2905f |
|
| /// File Name: |
tvp-overflow.txt |
Description:
|
Total Video Player version 1.03 M3U file local buffer overflow exploit that can bind a shell or spawn calc.exe.
| | Author: | fl0 fl0w | | Homepage: | http://fl0-fl0w.docspages.com/ | | File Size: | 6369 | | Last Modified: | Feb 1 11:10:02 2008 |
| MD5 Checksum: | 7ab0fddc14daf3fbd233fbf65bb64c38 |
|
| /// File Name: |
jessica_biel_naked_in_my_bed.c |
Description:
|
Linux kernel versions 2.6.17 through 2.6.24.1 vmslice local root exploit.
| | Author: | qaaz | | File Size: | 6264 | | Last Modified: | Feb 11 15:53:54 2008 |
| MD5 Checksum: | e3e4fa55ccc07d69a5f0667786003924 |
|
| /// File Name: |
tvp120-overflow.txt |
Description:
|
Total Video Player version 1.20 M3U file local buffer overflow exploit that can bind a shell or spawn calc.exe.
| | Author: | fl0 fl0w | | Homepage: | http://fl0-fl0w.docspages.com/ | | File Size: | 5916 | | Last Modified: | Feb 7 20:25:57 2008 |
| MD5 Checksum: | 4fb4cdac8a72a9e151819216d01dc535 |
|
| /// File Name: |
auracms162-sql.txt |
Description:
|
AuraCMS version 1.62 suffers from multiple remote SQL injection vulnerabilities.
| | Author: | NTOS-Team | | Homepage: | http://newhack.org/ | | File Size: | 5557 | | Last Modified: | Feb 17 21:08:14 2008 |
| MD5 Checksum: | 9b504e8abf1f6b5766e4bd4259c86aea |
|
| /// File Name: |
microtik-dos.txt |
Description:
|
MicroTik RouterOS version 3.2 and below SNMPd denial of service exploit.
| | Author: | ShadOS | | Homepage: | http://hellknights.void.ru/ | | File Size: | 5544 | | Last Modified: | Feb 4 14:40:40 2008 |
| MD5 Checksum: | 4d53afe7855f4980e15892d47a24d3b5 |
|
| /// File Name: |
affiliate-sqlxss.txt |
Description:
|
Affiliate Market versions 0.1 BETA cross site scripting and SQL injection exploit.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 5165 | | Last Modified: | Feb 14 13:14:05 2008 |
| MD5 Checksum: | ca48520d0ba517dea5b4c11adc607a38 |
|
| /// File Name: |
mihalism-sql.txt |
Description:
|
Mihalism Multi Host Download blind SQL injection exploit that makes use of users.php.
| | Author: | Moubik | | Homepage: | http://rstzone.org/ | | File Size: | 5049 | | Last Modified: | Feb 6 16:43:23 2008 |
| MD5 Checksum: | 5b6927bbcf0e839f8c6edb0234a42dda |
|
| /// File Name: |
ablog-sqlxss.txt |
Description:
|
A-Blog version 0.2 remote SQL injection exploit along with cross site scripting vulnerability details.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 5030 | | Last Modified: | Feb 4 14:37:41 2008 |
| MD5 Checksum: | 00548d4444e4f5e3db374e787c1cd18d |
|
| /// File Name: |
blogphp-sql.txt |
Description:
|
BlogPHP version 0.2 remote SQL injection exploit along with cross site scripting vulnerability details.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 5005 | | Last Modified: | Feb 4 14:35:59 2008 |
| MD5 Checksum: | 30fb4b685a4f9b02c1907ac664083eed |
|
| /// File Name: |
DSECRG-08-015.txt |
Description:
|
Dokeos E-Learning System version 1.8.4 suffers from multiple SQL injection and cross site scripting vulnerabilities.
| | Author: | Sh2kerr, Stas Svistunovich | | Homepage: | http://www.dsec.ru/ | | File Size: | 4817 | | Last Modified: | Feb 20 00:07:49 2008 |
| MD5 Checksum: | 0962f6debaa8fedf66c71abb3a7f2c8a |
|
| /// File Name: |
openrealty-rfi.txt |
Description:
|
Open Realty version 2.4.3 suffers from a remote file inclusion vulnerability.
| | Author: | PitBull Crew | | File Size: | 4801 | | Last Modified: | Feb 12 22:03:35 2008 |
| MD5 Checksum: | 2b4aaf189113c19fa95f5bde78da15e5 |
|
| /// File Name: |
phpprofiles-rfi.txt |
Description:
|
phpProfiles version 4.5.2 appears susceptible to a remote file inclusion vulnerability.
| | Author: | CraCkEr | | File Size: | 4791 | | Last Modified: | Feb 25 13:08:37 2008 |
| MD5 Checksum: | 93e7be974249161974adf0fc7bf2f128 |
|
| /// File Name: |
groupe-rfi.txt |
Description:
|
GROUP-E version 1.6.41 suffers from a remote file inclusion vulnerability.
| | Author: | CraCkEr | | File Size: | 4591 | | Last Modified: | Feb 27 21:37:44 2008 |
| MD5 Checksum: | bbffd69ee536b82c53330ea105a20935 |
|
| /// File Name: |
phpuserbase-rfi.txt |
Description:
|
phpUserBase version 1.3b suffers from a remote file inclusion vulnerability in unverified.inc.php.
| | Author: | CraCkEr | | File Size: | 4584 | | Last Modified: | Feb 25 14:15:29 2008 |
| MD5 Checksum: | edcb812c0859316fb04ddd763f16a10f |
|
| /// File Name: |
mybbprivate-sql.txt |
Description:
|
MyBulletinBoard aka MyBB versions 1.2.11 and below SQL injection exploit that makes use of private.php.
| | Author: | F | | Related Exploit: | waraxe-2008-SA064.txt | | File Size: | 4446 | | Last Modified: | Feb 6 14:41:29 2008 |
| MD5 Checksum: | 574b08fc38cff78e650aa5259f3c272d |
|
| /// File Name: |
ghostscript-poc.txt |
Description:
|
Proof of concept exploit that demonstrates a buffer overflow vulnerability in Ghostscript versions 8.61 and below.
| | Author: | Will Drewry | | Related File: | ghostscript-overflow.txt | | File Size: | 4416 | | Last Modified: | Mar 3 14:16:56 2008 |
| MD5 Checksum: | 68b371030bdbb5deb3fbdb2b286fa2ef |
|
| /// File Name: |
pigyard-multi.txt |
Description:
|
Pigyard Art Gallery suffers from administrative bypass and SQL injection vulnerabilities.
| | Author: | ZoRLu | | Homepage: | http://www.yildirimordulari.org/ | | File Size: | 4411 | | Last Modified: | Feb 25 14:16:44 2008 |
| MD5 Checksum: | 132a7de7546609c8516492217f55a1c4 |
|
|
|
|
|