This archive contains all of the 448 exploits added to Packet Storm in November, 2009.
3a2d0b09f8a74b536ed490a5c5591810XOOPS Smart Media version 0.85 suffers from a cross site scripting vulnerability.
6847e10e23824b771c7e0f53fab993f3The XOOPS Content module version 0.5 suffers from a remote SQL injection vulnerability.
d83955755f5f71affffff18ba3e6ebf4The Joomla Quick News component suffers from a remote SQL injection vulnerability.
19e7ff63b67f378fd56f9b7ec61e040aThe Microsoft Technet site suffers from a cross site scripting vulnerability.
6441127e068e8e9547504603366b23d2Eshopbuilde CMS suffers from a remote SQL injection vulnerability.
d4f878caa4b12b9c3b7208512700c881dotDefender version 3.8-5 suffers from a remote command execution vulnerability.
160328ae5b04babb001d86821bd62007Robert Zimmerman PHP / MYSQL scripts suffer from an administrative bypass vulnerability.
1937c292c642910c45fb2ef2c10a7985The Micronet SP1910 Data Access Controller user interface suffers from a cross site scripting vulnerability.
481e4f68f42859127ea9159acea72f2cMillenium MP3 Studio version 2.0 buffer overflow exploit that creates a malicious .pls file.
b61b67d539912a1c3f8abe14cceb9f72Adapt CMS Lite version 1.5 suffers from a remote file inclusion vulnerability. This is the same issue that affected 1.4.
6ced16079e7b0f02153c925513b6869aSugar CRM versions 5.5.0.RC2 and 5.2.0j suffer from remote SQL injection, unauthorized access, remote file inclusion, and code execution vulnerabilities.
62d57fc4c68a29e58d623580a2ce9159FreeBSD local root exploit that leverages a bug in the Run-Time Link-Editor (rtld). Versions 7.1 and 8.0 are vulnerable.
cbcc98addf614846e89865ec7b0e193fXxasp version 3.3.2 suffers from a remote SQL injection vulnerability.
e662fa8a9bd882e292ea848aad37f9c0Eureka Mail Client remote buffer overflow exploit for XP SP3 English egghunter edition.
1bb7d1e2361dad4f11d730bb9663f975The Joomla Music Gallery component suffers from a remote SQL injection vulnerability.
796689dd5dd1be2207af36b29250d0ecElxis CMS suffers from a local file disclosure vulnerability.
a4fca85e9f77722759dc886fd22e60d4Oracle SYS.LT.MERGEWORKSPACE exploit that grants DBA permissions to an unprivileged user.
0caff07fa6764014d34718102e3497bfOracle SYS.LT.REMOVEWORKSPACE exploit that grants DBA permissions to an unprivileged user.
f41c804a13eb1ef70b590681ccea0aecOracle SYS.LT.COMPRESSWORKSPACETREE exploit that grants DBA permissions to an unprivileged user.
7a5070a07d3c49bad91dc9555a805682Oracle ctxsys.drvxtabc.create_tables exploit that grants DBA permissions to an unprivileged user. This version uses an evil cursor technique.
213928693d65f40e6f45150351d69835Oracle ctxsys.drvxtabc.create_tables exploit that grants DBA permissions to an unprivileged user.
530e2fcc7b0fa4758298209db0e79f9eSweetRice versions 0.5.3 and below suffer from remote and local file inclusion vulnerabilities.
b46cf962896f315d87bf1a6dec158bb7MuPDF and SumatraPDF suffer from a buffer overflow vulnerability. Proof of concept pdf included.
73751c3c590fdd3c9248b9c2f88dd4c8SweetRice versions 0.5.0 and below suffer from a remote file inclusion vulnerability.
3d27a18a44df86988ad5170e0dc8201f