security without boundaries
Showing 1 - 19 of 19 RSS Feed

Files Date: 2012-01-03

OpenEMR 4.1.0 SQL Injection
Posted Jan 3, 2012
Authored by Canberk BOLAT

OpenEMR is affected by a remote SQL injection vulnerability in version 4.1.0.

tags | exploit, remote, sql injection
MD5 | e5fc30bfd7ed1f43dfdbc4641e3dd252
Bugzilla Chart Generator Cross Site Scripting
Posted Jan 3, 2012
Site redteam-pentesting.de

RedTeam Pentesting discovered a cross site scripting vulnerability in Bugzilla's chart generator during a penetration test. If attackers can persuade users to click on a prepared link or redirected them to such a link from an attacker-controlled website, they are able to run arbitrary JavaScript code in the context of the Bugzilla installation's domain. Versions affected include 2.17.1 to 3.4.12, 3.5.1 to 3.6.6, 3.7.1 to 4.0.2 and 4.1.1 to 4.1.3.

tags | exploit, arbitrary, javascript, xss
advisories | CVE-2011-3657
MD5 | ecb79fb6812f4fdef542de9e41d1e82b
Mavili Guestbook 200711 Cross Site Scripting / SQL Injection
Posted Jan 3, 2012
Authored by demonalex

Mavili Guestbook version 200711 suffers from bypass, cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
MD5 | 7f81f065bf7c615f63fc8c9a060f46c8
Tiny Guest Book Cross Site Scripting
Posted Jan 3, 2012
Authored by G13

Tiny Guest Book suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 54fe5383e0ea258a6898102a2b7cc625
OpenKM Document Management System 5.1.7 Command Execution
Posted Jan 3, 2012
Authored by Cyrill Brunschwiler | Site csnc.ch

OpenKM Document Management System version 5.1.7 suffers from a remote command execution vulnerability.

tags | exploit, remote
MD5 | c4d18950cda8be8a03c3ec22caa0c2f5
OpenKM Document Management System 5.1.7 Privilege Escalation
Posted Jan 3, 2012
Authored by Cyrill Brunschwiler | Site csnc.ch

OpenKM Document Management System version 5.1.7 suffers from an authenticated privilege escalation vulnerability.

tags | exploit
MD5 | c854b82aaf61acf780dff9ac73f4b767
BigACE CMS 2.7.5 Cross Site Scripting
Posted Jan 3, 2012
Authored by demonalex

BigACE CMS version 2.7.5 suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | f792be4bc09acd64f5cc300556b9b3f5
Debian Security Advisory 2378-1
Posted Jan 3, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2378-1 - Several vulnerabilities have been discovered in ffmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders for QDM2, VP5, VP6, VMD and SVQ1 files could lead to the execution of arbitrary code.

tags | advisory, arbitrary, vulnerability
systems | linux, debian
advisories | CVE-2011-4351, CVE-2011-4353, CVE-2011-4364, CVE-2011-4579
MD5 | 3888295550ac94884c3f6b2fd4757190
MyStore Tienda Virtual 2.0 SQL Injection
Posted Jan 3, 2012
Authored by Easy Laster

MyStore Tienda Virtual version 2.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 7cf5c707d8f383147cc0f2999bf3f5a2
Peta Zetas IDS Testing Tool
Posted Jan 3, 2012
Authored by Alberto Ortega

PZIDS (Peta Zetas IDS) is a tool to test if your IDS is detecting threats properly. Written in Python.

tags | tool, sniffer, python
MD5 | b78ed32220ffb538532f721a2be7a485
StreamDown 6.8.0 Buffer Overflow
Posted Jan 3, 2012
Authored by Fady Mohamed Osman | Site metasploit.com

This Metasploit module exploits Stream Down version 6.8.0 using a SEH based buffer overflow that is triggered when processing the server response packet. During the overflow a structured exception handler is overwritten.

tags | exploit, overflow
MD5 | 8d5b215cd9f32d4686c7433487ed0631
Apigee Facebook API Cross Site Scripting
Posted Jan 3, 2012
Authored by Asish Agarwalla

The Apigee Facebook API suffers from a cross site scripting vulnerability.

tags | advisory, xss
MD5 | 9a44567514e68595badf32581c187bc4
WordPress Comment Rating Cross Site Scripting / SQL Injection
Posted Jan 3, 2012
Authored by The Evil Thinker

The WordPress Comment Rating plugin suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
MD5 | a53a0c66c38d07d2715138d38faf7c36
MyStore Tienda Virtual SQL Injection
Posted Jan 3, 2012
Authored by Arturo Zamora

MyStore Tienda Virtual suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 4c24b62faa7e261af2d812291f475b53
Technitium MAC Address Changer
Posted Jan 3, 2012
Authored by Shreyas Zare | Site tmac.technitium.com

Technitium MAC Address Changer allows you to change Media Access Control (MAC) Address of your Network Interface Card (NIC) irrespective to your NIC manufacturer or its driver. It has a very simple user interface and provides ample information regarding each NIC in the machine.

MD5 | 2a51808af6f03fff9bd076730e9fe281
Linux Kernel Hooking / Data Manipulations / Root Exploits
Posted Jan 3, 2012
Authored by Turkeshan

Whitepaper called Linux Kernel Hooking, Data Manipulations and Making Root Exploits. Written in Turkish.

tags | paper, kernel, root
systems | linux
MD5 | 28fae139bde9a4dc5de620503482207d
Secunia Security Advisory 47376
Posted Jan 3, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Debian has issued an update for ipmitool. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

tags | advisory, denial of service, local
systems | linux, debian
MD5 | e1e30bba20c25b51497e5a9ebb0cdbf2
Secunia Security Advisory 47434
Posted Jan 3, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two vulnerabilities have been discovered in Rapidleech, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks.

tags | advisory, vulnerability, xss
MD5 | 5e0eecadb1cc1d30dcbb11e377b085c3
Secunia Security Advisory 47427
Posted Jan 3, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in the TheCartPress plugin for WordPress, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
MD5 | 6d070c1e2ebc8fcb66a368479233f3d2
Page 1 of 1
Back1Next

File Archive:

February 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    36 Files
  • 2
    Feb 2nd
    46 Files
  • 3
    Feb 3rd
    45 Files
  • 4
    Feb 4th
    27 Files
  • 5
    Feb 5th
    12 Files
  • 6
    Feb 6th
    26 Files
  • 7
    Feb 7th
    48 Files
  • 8
    Feb 8th
    54 Files
  • 9
    Feb 9th
    28 Files
  • 10
    Feb 10th
    50 Files
  • 11
    Feb 11th
    21 Files
  • 12
    Feb 12th
    26 Files
  • 13
    Feb 13th
    34 Files
  • 14
    Feb 14th
    18 Files
  • 15
    Feb 15th
    52 Files
  • 16
    Feb 16th
    32 Files
  • 17
    Feb 17th
    53 Files
  • 18
    Feb 18th
    49 Files
  • 19
    Feb 19th
    13 Files
  • 20
    Feb 20th
    27 Files
  • 21
    Feb 21st
    47 Files
  • 22
    Feb 22nd
    45 Files
  • 23
    Feb 23rd
    41 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close