Packet Storm new exploits for September, 2008.
54bac55ec40e8fd5a7879702bc5be31bSG Real Estate Portal version 2.0 suffers from an insecure cookie handling vulnerability.
3dc68d2f801fb24b4ffcc207aeb73eeeSG Real Estate Portal version 2.0 remote blind SQL injection exploit.
6bc583b1e665eeae176eee07cde4cb2dSG Real Estate Portal version 2.0 suffers from blind SQL injection and local file inclusion vulnerabilities.
087e027c32732db3cd30868b944fc33aAutodesk DWF Viewer Control / LiveUpdate Module remote code execution exploit.
99bab3b6a9842988632235ad6239a43aFAQ Management script suffers from a remote SQL injection vulnerability.
63c77f29d458a44544f75e03d28f359aA4Desk PHP Event Calendar suffers from a remote file inclusion vulnerability.
b96b41639284183cd9f224aba5ba0ea5moziloWiki versions 1.0.1 and below suffer from directory traversal, cross site scripting, and session fixation vulnerabilities.
aa39ad4835751870219451376f118696WordPress MU versions below 2.6 suffer from a cross site scripting vulnerability in wpmu-blogs.php.
bcd9422dde4e5978e3ed325d56a1166fMicrosoft Internet Explorer 7 denial of service exploit that is rumored to work on Konqueror as well.
d0bfa30abedb808f52cbb7040c4040deGoogle Chrome version 0.2.149.30 and Safari version 3.1.2 suffer from a denial of service vulnerability.
16a7fe6dc7df5b95a547848b99b88d4beFront versions 3.5.1 build 2710 and below suffer from a remote arbitrary upload vulnerability.
1b8215f31e5b53a8bba20672ebcc1f5fMicronation Banking System version 1.5.0 suffers from multiple remote file inclusion vulnerabilities.
d6c560b8799e7774005fd9802f680788Arab CMS suffers from a local file inclusion vulnerability in rss.php.
8d61f4209b1cf8d90aaeea11df3e2d7dWireshark version 1.0.x .ncf file local denial of service exploit.
7b8b383ea34be162171d59302f71ab13Easy4U CMS suffers from remote SQL injection and cross site scripting vulnerabilities in main.php.
00c8d8dd104cb9eb66d84bbee3a37df3PG Matchmaking script suffers from multiple remote SQL injection vulnerabilities.
17b65b25c68548424dc05352404e7927Microsoft Internet Explorer GDI+ proof of concept exploit that leverages the vulnerability discussed in MS08-0520.
ca5b6a2292e99222dd96d741389215b1Microsoft Windows Explorer unspecified .zip file denial of service exploit.
ce0095ebbd268604ded7e78414acada9Events Calendar version 1.1 suffers from a remote file inclusion vulnerability.
0d5cb4c63d6644dc6435d3219dbf3962The PHP-Fusion Freshlinks module suffers from a remote SQL injection vulnerability.
cd6b3da5efd866e5d2af63b3eb5e3f2ePost Comments version 3.0 suffers from an insecure cookie handling vulnerability.
8bdcf703d9e501b9739b5cd9fcb80993xbtit version 2.0.0 suffers from a remote SQL injection vulnerability in scrape.php.
bdfb0f53bc3d2bf2aea30f48ce219bd4Webbiscuits Events Calendar version 1.1 suffers from a remote file inclusion vulnerability.
66a82bfba0eb008871dcb8345e2ebb11The Joomla imagebrowser component versions 0.1.5 RC2 and below suffer from a directory traversal vulnerability.
de6f45358a5095e139afda1be7d89f78