Packet Storm new exploits for March, 2008.
37abad183221a7e9b308177f5251e8632X ThinClientServer versions 5.0_sp1-r3497 and below along with TFTPd.exe version 3.2.0.0 and below suffer from a directory traversal vulnerability.
1fc0c4d91b8ac516db4384ba6d0bba71VbSeo suffers from a cross site scripting vulnerability.
869cb803261d04d741c1f03d0d2b8642Proviso SiteKiosk suffers from a bypass flaw that allows for file downloads.
cf2a25f38f9ef36c4c13d1f1ad97bc6amxBB module mx_blogs version 2.0.0-beta remote file inclusion exploit.
58630e35b5d2e4e4e7e4e9fc56708ae1The Woltlab Burning Board Add-on JGS-Treffen suffers from a SQL injection vulnerability.
0707df77f344aa496952e226d0ae9ed3The Wordpress Download plugin suffers from a SQL injection vulnerability.
9ce2db893d1e736e3786dc7109363e6bAuraCMS versions 2.0 through 2.2.1 security code bypass and add administrator exploit.
712057a75b49ad6414cca3c757d2c833phpSpamManager version 0.53 beta suffers from a remote file disclosure vulnerability in body.php.
8df03bc73f054e8c8e7fc80b7a4a9408Microsoft Office XP SP3 Powerpoint file buffer overflow exploit that spawns calc.exe. Based off of the vulnerability listed in MS08-016.
862448b46ec7362c469ba9d98a907038Efestech Video version 5.0 suffers from a SQL injection vulnerability.
a00801562a7c9139389e1f47f91438d5JShop versions 1.x through 2.x suffer from a local file inclusion vulnerability in page.php.
2259de893612264bde3af2268f4eb9b8KISGB versions 5.1.1 and below suffer from a local file inclusion vulnerability.
e4f42b7c57aaecb6ae696d4fa2ebdf59Smoothflash suffers from a SQL injection vulnerability in admin_view_image.php.
c2809e62a6c6e87890ab1a80ba045813Microsoft Windows Explorer unspecified .DOC file denial of service exploit.
f37a9ee1d4a1240f3c57310b294a0bf3Visual Basic suffers from a local stack overflow vulnerability in vbe6.dll that can lead to a denial of service condition.
4cb49535a3ef1355c4211ee7f7ec9e4cCuteFlow version 1.5.0 suffers from SQL injection and cross site scripting vulnerabilities.
7ce3317e8139880959000094ec922651The Joomla MyAlbum component version 1.0 suffers from a remote SQL injection vulnerability.
8df24cc589a828999ddf28ea672be981DigiDomain version 2.2 suffers from cross site scripting vulnerabilities.
74e28c6532efe795097ca6df9f86a940JAF-CMS version 4.0 RC2 suffers from remote file inclusion vulnerabilities.
5ada725dfde0f0aa16dd8f5f34ab828aGeoCarts suffers from cross site scripting and remote file inclusion vulnerabilities.
c8c76d67a78c494cd32fd548d2e0642aDemonstration exploit code for IBM solidDB versions 6.00.1018 and below which suffer from format string, crash, NULL pointer, and server termination vulnerabilities.
8d76275f73d80dc5ec96a9080080b81cInvision Power Board versions 2.3.x and below allow for an arbitrary iframe insertion.
2803621c6588981cb6f4cb3a42bd6a67Quick TFTP Pro version 2.1 SEH overflow zero day exploit that binds a shell to port 4444.
a03f08a6c1f4fa38a7d978b59f88c60dTFTP Server for Windows version 1.4 ST zero day buffer overflow exploit. Binds a shell to port 4444.
bc8068f0c5acf9c1a4157c0e9f9b7043