knowledge is security
Showing 1 - 18 of 18 RSS Feed

Files Date: 2012-01-28

FAA US Academy SQL Injection
Posted Jan 28, 2012
Site vulnerability-lab.com

FAA US Academy suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
MD5 | d7a7c911afa34199da4bbc3f3a843f8a
eBank IT Online Banking Cross Site Scripting
Posted Jan 28, 2012
Authored by Chokri Ben Achor | Site vulnerability-lab.com

eBank IT Online Banking suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | b943436f778b07d5b2ca90bcfacf1310
Joomla Visa SQL Injection / Local File Inclusion
Posted Jan 28, 2012
Authored by the_cyber_nuxbie

The Joomla Visa component suffers from local file inclusion and remote SQL injection vulnerabilities.

tags | exploit, remote, local, vulnerability, sql injection, file inclusion
MD5 | d2f47435abdb727fab6b0ad37b89d75e
DGC SQL Injection
Posted Jan 28, 2012
Authored by Skote Vahshat

DGC suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 81f586badd50a7e58ed071f62fee619c
Joomla Cmotour SQL Injection
Posted Jan 28, 2012
Authored by the_cyber_nuxbie

The Joomla Cmotour component suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | e8731f676f600895a9a49016ec8cd379
Neda Rayaneh CMS SQL Injection
Posted Jan 28, 2012
Authored by M4sT3r4N0nY

Neda Rayaneh CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 4fce8b30fa7e31fb8b6fa9506db9b881
TND Media CMS SQL Injection
Posted Jan 28, 2012
Authored by Am!r | Site irist.ir

TND Media CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 07c886016a0ff681687932eff1212bea
FatCat SQL Injector
Posted Jan 28, 2012
Authored by Sandeep K

This is an automatic SQL Injection tool called FatCat. It has features that help you to extract the database information, table information, and column information from a web application.

tags | tool, web, scanner, sql injection
systems | unix
MD5 | 4f817b144c8f53343c8aa637f785cfa7
Silverstripe CMS Cross Site Scripting
Posted Jan 28, 2012
Authored by Karthik R

Silverstripe CMS suffers from a cross site scripting vulnerability in the page title module.

tags | exploit, xss
MD5 | 2214fd112af4a84325c1cf7a4cbc530c
Lifesystems Cross Site Scripting
Posted Jan 28, 2012
Authored by Skote Vahshat

Lifesystems suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 8654305d1a8ee681e6ce0e6b9c813fa3
Motigo Forums/Calendar/Guestbook Cross Site Scripting
Posted Jan 28, 2012
Authored by Sony

Motigo Forums/Calendar/Guestbook suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 3d3cc287c96a1a13d963c88faab688f3
Gitorious Remote Command Execution
Posted Jan 28, 2012
Authored by joernchen | Site phenoelit.de

Gitorious versions prior to 2.1.1 suffer from a remote command execution vulnerability.

tags | exploit, remote
MD5 | 29144dc4f809ee2b0f9f56dd45971982
HP Diagnostics Server magentservice.exe Overflow
Posted Jan 28, 2012
Authored by AbdulAziz Hariri, hal | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in HP Diagnostics Server magentservice.exe service. By sending a specially crafted packet, an attacker may be able to execute arbitrary code. Originally found and posted by AbdulAziz Harir via ZDI.

tags | exploit, overflow, arbitrary
advisories | CVE-2011-4789, OSVDB-72815
MD5 | e1ffea648751482c32e081239f6df96f
MS12-004 midiOutPlayNextPolyEvent Heap Overflow
Posted Jan 28, 2012
Authored by sinn3r, juan vazquez, Shane Garrett | Site metasploit.com

This Metasploit module exploits a heap overflow vulnerability in the Windows Multimedia Library (winmm.dll). The vulnerability occurs when parsing specially crafted MIDI files. Remote code execution can be achieved by using Windows Media Player's ActiveX control. Exploitation is done by supplying a specially crafted MIDI file with specific events, causing the offset calculation being higher than how much is available on the heap (0x400 allocated by WINMM!winmmAlloc), and then allowing us to either "inc al" or "dec al" a byte. This can be used to corrupt an array (CImplAry) we setup, and force the browser to confuse types from tagVARIANT objects, which leverages remote code execution under the context of the user. At this time, for IE 8 target, JRE (Java Runtime Environment) is required to bypass DEP (Data Execution Prevention). Note: Based on our testing, the vulnerability does not seem to trigger when the victim machine is operated via rdesktop.

tags | exploit, java, remote, overflow, code execution, activex
systems | windows
advisories | CVE-2012-0003, OSVDB-78210
MD5 | e13897802c519c03ae5164b1d2ecb919
AWS Hash Collisions
Posted Jan 28, 2012
Site adacore.com

AdaCore Security Advisory - All AWS releases and wavefronts prior to 2012-01-21 suffer from hash collision vulnerabilities.

tags | advisory, vulnerability
MD5 | 033eef4cea8ba40ff2b4c809bc9b264e
Studio Manolibera Listarivisteuk SQL Injection
Posted Jan 28, 2012
Authored by Th4 MasK

Studio Manolibera's listarivisteuk.php suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | 4e1aa19b0abc9ab60f206f8111eab36d
Dark D0rk3r 0.5
Posted Jan 28, 2012
Authored by baltazar

Dark D0rk3r is a python script that performs dork searching and searches for local file inclusion and SQL injection errors.

Changes: New options added.
tags | tool, local, scanner, sql injection, python, file inclusion
systems | unix
MD5 | 889d6c7b94e9b4b4eca15f9e04ce9a86
IBBY SQL Injection
Posted Jan 28, 2012
Authored by Th4 MasK

IBBY's nouvelles.php suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection
MD5 | a6f587d132fea09875b4d577871e6fb8
Page 1 of 1
Back1Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close