acknowledge the elephant in the room
Showing 101 - 125 of 397 RSS Feed

Files

TWiki History TWikiUsers rev Parameter Command Execution
Posted Feb 23, 2010
Authored by B4dP4nd4 | Site metasploit.com

This Metasploit module exploits a vulnerability in the history component of TWiki. By passing a 'rev' parameter containing shell metacharacters to the TWikiUsers script, an attacker can execute arbitrary OS commands.

tags | exploit, arbitrary, shell
advisories | CVE-2005-2877
MD5 | 2484d1f845372d8b4a4a3cc3df399f1e
Easy FTP Server 1.7.0.2 Buffer Overflow
Posted Feb 23, 2010
Authored by athleet

Easy FTP Server version 1.7.0.2 remote buffer overflow exploit.

tags | exploit, remote, overflow
MD5 | 1142b312a82ca80068306eaf46c006e3
Coppermine Photo Gallery 1.4.14 picEditor.php Command Execution
Posted Feb 20, 2010
Authored by Janek Vind aka waraxe | Site metasploit.com

This Metasploit module exploits a vulnerability in the picEditor.php script of Coppermine Photo Gallery. When configured to use the ImageMagick library, the 'quality', 'angle', and 'clipval' parameters are not properly escaped before being passed. NOTE: Use of the ImageMagick library is a non-default option. However, a user can specify its use at installation time.

tags | exploit, php
advisories | CVE-2008-0506
MD5 | 348630ab822d73fca3d6902525794666
vBseo 3.1.0 Local File Inclusion
Posted Feb 20, 2010
Authored by ViRuSMaN

vBseo version 3.1.0 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
MD5 | 372aa0c7a496a2bee62b4492d386796a
VideoSearchScript Pro 3.5 Cross Site Scripting
Posted Feb 20, 2010
Authored by listi kurdistani

VideoSearchScript Pro version 3.5 suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 9941f2cc175fc630645236a59b24df7c
vBulletin 4.0.2 Cross Site Scripting
Posted Feb 20, 2010
Authored by indoushka

vBulletin version 4.0.2 suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 36a5005ae53eb8772ae6e2a6f1192a52
Coupons Direct Access Bypass
Posted Feb 20, 2010
Authored by indoushka

Coupons suffers from a direct access administrative bypass vulnerability.

tags | exploit, bypass
MD5 | 5887f82eafb23b35b11b2de6d5e62b05
Symev CMS SQL Injection
Posted Feb 20, 2010
Authored by Metropolis

Symev CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 0ce7c0745339ccc89ffad3c0ba5ed6bb
phpBugTracker 1.0.1 File Disclosure
Posted Feb 20, 2010
Authored by ViRuSMaN

phpBugTracker version 1.0.1 suffers from a file disclosure vulnerability.

tags | exploit, info disclosure
MD5 | 32cef8a0f4f80ef27d5cef18089af9b4
FlatFile Password Disclosure
Posted Feb 20, 2010
Authored by ViRuSMaN

FlatFile System suffers from a remote password disclosure vulnerability.

tags | exploit, remote, info disclosure
MD5 | acfecb7f1d688db654eb1e793f527726
TimeClock Cross Site Request Forgery
Posted Feb 20, 2010
Authored by ViRuSMaN

TimeClock cross site request forgery add administrator exploit.

tags | exploit, csrf
MD5 | 3bfacf29cc5c18ec223dbb2d9eb2c3ae
phpAutoVideo Cross Site Request Forgery
Posted Feb 20, 2010
Authored by GoLdeN-z3r0

phpAutoVideo suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
MD5 | 4d30bc155571221a02a79eee40088322
Joomla Recipe SQL Injection
Posted Feb 20, 2010
Authored by Fl0riX

The Joomla Recipe component suffers from remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, sql injection
MD5 | 2936aa3564c4f114a551d37c12793881
Litespeed Web Server 4.0.12 Cross Site Request Forgery / Cross Site Scripting
Posted Feb 20, 2010
Authored by d1dn0t

Litespeed Web Server version 4.0.12 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, web, vulnerability, xss, csrf
MD5 | ce74ef87bb422bc0736a8e2839357e5f
WSC CMS SQL Injection
Posted Feb 20, 2010
Authored by Phenom

WSC CMS suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
MD5 | 8e0d13e098b3311e67ede3b4f67af506
Amelia CMS SQL Injection
Posted Feb 20, 2010
Authored by Ariko-Security

Amelia CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | cfa93d450d437ae2b513d6180829d1d3
Easy FTP Server 1.7.0.2 Buffer Overflow
Posted Feb 20, 2010
Authored by ThE g0bL!N

Easy FTP Server version 1.7.0.2 HTTP remote buffer overflow exploit.

tags | exploit, remote, web, overflow
MD5 | f64bf41e2f128c4b5b6a732075f25d65
Kusaba X 0.9 Cross Site Scripting / Cross Site Request Forgery
Posted Feb 20, 2010
Authored by systemx00

Kusaba X versions 0.9 and below suffer from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
MD5 | b7f49e39bb6a267c46ea1006f7dcf93d
Trixbox 2.2.4 SQL Injection
Posted Feb 20, 2010
Authored by NorSlacker

Trixbox version 2.2.4 suffers from a remote SQL injection vulnerability in PhonecDirectory.php.

tags | exploit, remote, php, sql injection
MD5 | cd1129948fa822023b87fafceca0a22f
PHP-Kit 1.6.1 SQL Injection
Posted Feb 19, 2010
Authored by Easy Laster

PHP-Kit version 1.6.1 suffers from a remote SQL injection vulnerability in member.php.

tags | exploit, remote, php, sql injection
MD5 | 46555c0554552701c2f04dd08748fd4a
Joomla Community Polls Local File Inclusion
Posted Feb 19, 2010
Authored by kaMtiEz | Site indonesiancoder.com

The Joomla Community Polls component suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
MD5 | 231b0080cfec609c4a5154dca2612837
SphereCMS 1.1 Alpha Blind SQL Injection
Posted Feb 19, 2010
Authored by AmnPardaz Security Research Team | Site bugreport.ir

SphereCMS version 1.1 Alpha suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | b7e2a1e5e04606fb621b1425e933a696
New-CMS 1.08 LFI / XSS / XSRF / Shell Upload
Posted Feb 19, 2010
Authored by Alberto Fontanella

New-CMS version 1.08 suffers from cross site request forgery, cross site scripting, local file inclusion and shell upload vulnerabilities.

tags | exploit, shell, local, vulnerability, xss, file inclusion, csrf
MD5 | 39d6ce1a45885ec8d935830e7ce48508
Open Source Classifieds 1.1.0 Alpha Cross Site Scripting / SQL Injection
Posted Feb 19, 2010
Authored by Sioma Labs

Open Source Classifieds version 1.1.0 Alpha suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
MD5 | 6ce5bef409461fcc5c50fc32b3a1b57e
FileApp 1.7 For iPhone / iPod Remote Denial Of Service
Posted Feb 19, 2010
Authored by Ale46

FileApp version 1.7 for iPhone / iPod remote denial of service exploit.

tags | exploit, remote, denial of service
systems | apple, iphone
MD5 | c0099f631a52cda4c304d5792578c7fd
Page 5 of 16
Back34567Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Armenia Jails Bredolab Botmaster For 4 Years
Posted May 24, 2012

tags | headline, government, cybercrime, botnet, fraud
Police Given 350 Mobile Fingerprint Scanners For Olympics
Posted May 24, 2012

tags | headline, government, privacy, britain
Researcher Needles Oracle Over Java Security
Posted May 24, 2012

tags | headline, flaw, oracle, java
35,000 Passwords Reset After BigPond GameArena Hacked
Posted May 24, 2012

tags | headline, hacker, data loss, password
Indian SMBs Facing Advanced Attack Threats
Posted May 23, 2012

tags | headline, hacker, india, denial of service, symantec
Jailed Facebook Hack Brit Targeted Justin Bieber's Girlfriend
Posted May 23, 2012

tags | headline, hacker, britain, facebook, social
123-Reg Hosted Websites Go Offline After 'China Attack'
Posted May 23, 2012

tags | headline, china, denial of service
Google To Alert Thousands Over Loss Of Internet Risk From DNSChanger Trojan
Posted May 23, 2012

tags | headline, malware, trojan, dns, google
Microsoft's Rozzle Bolsters Drive-By Malware Defenses
Posted May 22, 2012

tags | headline, malware, microsoft
Chinese Social Network To Recruit In-House Censor
Posted May 22, 2012

tags | headline, china, social, twitter, censorship
View More News →
packet storm

© 2012 Packet Storm. All rights reserved.

close