Packet Storm new exploits for November, 2008.
4c82f1f29e6626dc54ea80675384f8e2Broadcast Machine version 0.1 suffers from multiple remote file inclusion vulnerabilities.
8198cfbd1086bbe4e2f09a3b8a923f06cpCommerce version 1.2.6 suffers from input variable overwrite and authentication bypass vulnerabilities.
8a67c6d9744fadb9a83cc798169b41a3Minimal Ablog version 0.4 suffers from file upload, administrative bypass, and remote SQL injection vulnerabilities.
9ec5f0536ae171d5ba3242bf27d501f8KTP Computer Customer Database CMS suffers from a blind SQL injection vulnerability.
ad0a2f2f16fa3b1a3ffc081ac17ba2c3KTP Computer Customer Database CMS local file inclusion exploit.
908db80332718321ad09a1a444a66cd4Active Bids version 3.5 suffers from a blind SQL injection vulnerability.
e951d6ce10698f269567ffffa5991644Active Test version 2.1 suffers from a blind SQL injection vulnerability.
777dc043442c70ccc8f1678ed52ef493Active Web Mail version 4 suffers from a blind SQL injection vulnerability.
5598c51144c84d9bb9c2904247b31dbfActive Votes version 2.2 suffers from a blind SQL injection vulnerability.
4c15393b3f1c524c9598b5e245667cebOraMon version 2.0.1 suffers from a remote configuration file disclosure vulnerability.
5219239d7b4f352e07fe99b998823402ASPThai.NET Forum version 8.5 suffers from a remote database disclosure vulnerability.
37cc7d80a9c3d5f89e3a4887580eb457OpenForum version 0.66 Beta remote administrator password reset exploit.
f9f98107c5d6c44bd400b28443984d22Active Business Directory version 2 suffers from a remote blind SQL injection vulnerability.
2bc454ed304fa0e9367deb91d9af4985Active Time Billing version 3.2 suffers from a SQL injection vulnerability that allows for authentication bypass.
c969118f9f2d1e530e81adc693c8667fActive Price Comparison version 4 suffers from a blind SQL injection vulnerability.
7e96990233ac30d798122a7bd89e8a31Active Photo Gallery version 6.2 suffers from a SQL injection vulnerability that allows for authentication bypass.
aa0269a9d4eefd9afa57a26c735328b5Active Web Helpdesk version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
e27528ffd28fca522f5a23d5206433b8Active Web Mail version 4 suffers from a blind SQL injection vulnerability.
9673d6c429848b0389b0267dae62b031Lito Lite CMS remote SQL injection exploit that makes use of cate.php.
100fe695f03fd188610bf6dc8dad05abQuick Tree View .NET version 3.1 suffers from a qtv.mdg database disclosure vulnerability.
9419fdf8c7f31d4676dcd182d0dcfbb2CMS Made Simple version 1.4.1 suffers from a local file inclusion vulnerability.
54add7e34d48f6a0e37e638fd84fd29bCain and Abel version 4.9.23 RDP file buffer overflow proof of concept exploit.
d98563b8a2db8788880b84876c0c7930iTunes version 8.0.2.20 and QuickTime 7.5.5 overflow proof of concept exploit that leverages .mov files.
6a0351cb21c3fe6bbb146e7356691997PHP TV Portal version 2.0 suffers from a remote SQL injection vulnerability in index.php.
cd201d53bb060b8eff42eff370fe74dc