This archive contains all of the 334 exploits added to Packet Storm in April, 2011.
f0a75b6f63bb645afc5b5e96c74f6caeThis Metasploit module exploits a stack buffer overflow in MJM QuickPlayer 1.00 beta 60a and QuickPlayer 2010 (Multi-target exploit). When opening a malicious s3m file in one of these 2 applications, a stack buffer overflow can be triggered, resulting in arbitrary code execution. This exploit bypasses DEP & ASLR, and works on XP, Vista & Windows 7.
26923cb503840c5307da191b999e0d76This Metasploit module exploits a stack buffer overflow in MJM Core Player 2011 When opening a malicious s3m file in this applications, a stack buffer overflow can be triggered, resulting in arbitrary code execution. This exploit bypasses DEP & ASLR, and works on XP, Vista & Windows 7.
20bedf4e31c1f9ca93bc6df99db159c9Microsoft Office Excel Axis properties record parsing buffer overflow proof of concept exploit that leverages the issue discussed in MS11-021.
4f5360a8806ec726349e3b14dde3a712SOOP Portal Raven version 1.0b suffers from a remote SQL injection vulnerability.
4de5194c23210bcbaab62a4339fae57bA vulnerability was discovered by Aung Khant that allows for exploitable SQL Injection attacks against a Joomla 1.6.0 install. This exploit attempts to leverage the SQL Injection to extract admin credentials, and use those credentials to execute arbitrary PHP code against the target. The vulnerability is due to a validation issue in /components/com_content/models/category.php that erroneously uses the "string" type whenever filtering the user supplied input. This issue was fixed by performing a whitelist check of the user supplied order data against the allowed order types, and also escaping the input.
1ad33dfea9c4661343e83233196f0d96phpGraphy version 0.9.13b suffers from cross site request forgery and cross site scripting vulnerabilities.
761375171156f440cdf983d309ad40a4The Cisco Linksys Wireless G Broadband Router WRT54G with firmware version 4.21.1 suffers from a cross site scripting vulnerability.
aa5edbdd4aa13e436f9c2ffc6695daaaxMatters AlarmPoint APClient version 3.2.0 suffers from a heap buffer overflow vulnerability.
e13e698bda246f85641a24baae0b325aNetOp Remote Control versions 8.0, 9.1, 9.2, and 9.5 buffer overflow exploit.
d9310f98ea6f926dfae34ee399458140Kusaba X versions 0.9.1 and below suffers from a cross site scripting vulnerability and a cross site request forgery vulnerability that allows for arbitrary SQL statement execution.
c657b34e03f675cf70b98daaa0a66b7cThis Metasploit module exploits a directory traversal and remote code execution flaw in EMC HomeBase Server 6.3.0. Note: This Metasploit module has only been tested against Windows XP SP3 and Windows 2003 SP2.
665a99f652864b621a656a91306656afThis Metasploit module exploits a vulnerability found in Subtitle Processor 7. By supplying a long string of data as a .m3u file, Subtitle Processor first converts this input in Unicode, which expands the string size, and then attempts to copy it inline on the stack. This results a buffer overflow with SEH overwritten, allowing arbitrary code execution.
8a330e0bce7b325ce0bad5d75ca70679Cook Media Web Development Group suffers from a remote SQL injection vulnerability.
19b935bfc74f9a7d3c7b69a458c5b145Daily Maui Photo Widget WordPress plugin version 0.2 suffers from a cross site scripting vulnerability.
5b966dd4b2653812e30b3be441a6bae2WP Photo Album WordPress plugin version 1.5.1 suffers from a cross site scripting vulnerability.
c6096b11f0c3042f45a9cc68ea45bcf5PixelGems remote file disclosure exploit that leverages a local file inclusion vulnerability.
b7db0ff9d2cc8c63b68ebdfdece32966eyeOS versions 1.9.0.2 and below suffer from a stored cross site scripting vulnerability.
1c6d64cfb48c85f77568faa9d02d2cdcShackleton Rollin suffers from a remote file disclosure vulnerability.
9a526c002f8c43f6cab8995d096cf33dBackupPC version 3.1.0 suffers from a cross site scripting vulnerability.
7eb3c187b977517365ec12f67b08dc89SE Software Technologies suffers from a remote SQL injection vulnerability.
cdba1aaf5f315558c2afeb2a401eb578libmodplug versions 0.8.8.2 and below .abc stack based buffer overflow proof of concept exploit.
60828e0af6a2e605f3ad080f56be3dc4xMatters AlarmPoint Java Web Server API version 3.2.1 suffers from a cross site scripting vulnerability.
0573456a01d3ebfa74aeffaa9f585535CMS Made Simple versions 1.9.4.1 and below remote shell upload exploit.
d85d49995a75ff06c5341e98e78fc24eClanSphere version 2011.0 suffers from shell upload and local file inclusion vulnerabilities.
257fe458dd5b530ad0237d998edef124