exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 26 - 50 of 50 RSS Feed

Files Date: 2010-07-08 to 2010-07-09

Freeciv 2.2.1 Denial Of Service
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

Freeciv version 2.2.1 suffers from denial of service vulnerabilities. Exploit included.

tags | exploit, denial of service, vulnerability
SHA-256 | 9d9e673eee5c1ce184752800c40c16a06d773e5a251dffdd15ceaf0a2a965042
Ghost Recon Advanced Warfighter 1 / 2 Overflows
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

Ghost Recon Advanced Warfighter versions 1 and 2 suffer from integer and array indexing overflows.

tags | advisory, overflow
SHA-256 | d973bcc1e6529953596abb97784dab67f32422d00caf4533203eb9fcab4cab84
Joomla ArtForms 2.1b7.2 RC2 Cross Site Scripting / SQL Injection / Directory Traversal
Posted Jul 8, 2010
Authored by Salvatore Fresta

The Joomla ArtForms component version 2.1b7.2 RC2 suffers from cross site scripting, remote SQL injection and directory traversal vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection, file inclusion
SHA-256 | 22ab97531f9b706153567472a552f4a7a1f71c20f48b853907cc14101e773a99
Pligg CMS 1.0.4 Cross Site Scripting
Posted Jul 8, 2010
Authored by Andrei Rimsa Alvares

Pligg CMS version 1.0.4 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 1e9a1773034cf732b523d0a050fc930039f7fe3bca02438d8d1f560b41f3e8bf
Mandriva Linux Security Advisory 2010-130
Posted Jul 8, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-130 - Certain invalid GSS-API tokens can cause a GSS-API acceptor (server) to crash due to a null pointer dereference in the GSS-API library. The updated packages have been patched to correct this issue.

tags | advisory
systems | linux, mandriva
advisories | CVE-2010-1321
SHA-256 | 5a363510cc86fa88ee8aa14537b88ea5f742ae16d68959c2ce6346cb423c3ff1
Mandriva Linux Security Advisory 2010-129
Posted Jul 8, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-129 - The krshd and v4rcp applications in MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion. The ftpd and ksu programs in MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. Certain invalid GSS-API tokens can cause a GSS-API acceptor (server) to crash due to a null pointer dereference in the GSS-API library. The updated packages have been patched to correct these issues.

tags | advisory, local
systems | linux, aix, mandriva
advisories | CVE-2006-3083, CVE-2006-3084, CVE-2010-1321
SHA-256 | 1229d0c29790afa2ad1dd4aa3ac27bed53aaf20094ab9e3f74e7252954698b5d
Cisco Security Advisory 20100707-snmp
Posted Jul 8, 2010
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - Cisco Industrial Ethernet 3000 (IE 3000) Series switches running Cisco IOS Software releases 12.2(52)SE or 12.2(52)SE1, contain a vulnerability where well known SNMP community names are hard-coded for both read and write access. The hard-coded community names are "public" and "private." Cisco recommends that all administrators deploy the mitigation measures outlined in the Workarounds section or perform a Cisco IOS Software upgrade. Cisco has released free software updates that address this vulnerability.

tags | advisory
systems | cisco
advisories | CVE-2010-1574
SHA-256 | 084a545cab9484dcba8b4e243ad0a6511c14890d442a8b0ee95360b78739111e
EA Battlefield 2 / Battlefield 2142 Multiple Arbitrary File Upload
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

The Refractor 2 engine in Battlefield 2 versions 1.50 and below and Battlefield 2142 versions 1.50 and below suffers from multiple arbitrary file upload vulnerabilities. Exploit included.

tags | exploit, arbitrary, vulnerability, file upload
SHA-256 | c719436be31cc3d812b256a0566b6669d91a7366594c74a49b5940eb5ce70c97
Sijio Community Software Cross Site Scripting / SQL Injection
Posted Jul 8, 2010
Authored by Sid3 effects

Sijio Community Software suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | 3ee8771359c68d7212cf3ffd593f8c08ba054d283886e2f0508d2103a7d32c62
Pith CMS 0.9.5.1 Local File Inclusion / Remote File Inclusion
Posted Jul 8, 2010
Authored by eidelweiss

Pith CMS version 0.9.5.1 suffers from local file inclusion and remote file inclusion vulnerabilities.

tags | exploit, remote, local, vulnerability, code execution, file inclusion
SHA-256 | 944f761de10c44c7f3d4242687d18efc85529fad04f075287e62dcdcf7ee445e
PBS Pro Race Condition
Posted Jul 8, 2010
Authored by Bartlomiej Balcerek

PBS Pro versions prior to 10.4 o+w race condition proof of concept exploit.

tags | exploit, proof of concept
SHA-256 | e5ef3ff55ecaffc75cef785be9136ba14ff0bdba919b16c5d79092a7dd9aa824
Joomla Agora 2.5.x Pantheon Local File Inclusion
Posted Jul 8, 2010
Authored by wishnusakti, inc0mp13te

The Joomla Agora component version 2.5.x Pantheon suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 01ba5957315cf61ac22adc2847d10f62e297b6131b1fa44d25d747e71530de2f
Ubuntu Security Notice 959-1
Posted Jul 8, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 959-1 - Denis Excoffier discovered that the PAM MOTD module in Ubuntu did not correctly handle path permissions when creating user file stamps. A local attacker could exploit this to gain root privileges.

tags | advisory, local, root
systems | linux, ubuntu
advisories | CVE-2010-0832
SHA-256 | ee80f6498671ddd1880de5fd9eef46ad026443c9acbf99faf79213e554bb0b74
DCP-Portal 7.0 Beta Cross Site Scripting
Posted Jul 8, 2010
Authored by Andrei Rimsa Alvares

DCP-Portal version 7.0 Beta suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 5f29d882be595d9768ed26abfbba408f87e79b18363a209d2a36f0ecf34f4367
Exponent CMS 0.97.0 Cross Site Scripting
Posted Jul 8, 2010
Authored by Andrei Rimsa Alvares

Exponent CMS version 0.97.0 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 8aa450c58f1fa570aae00c8156418bd6234276a19273404886efb1529db1b33e
GSM SIM Utility Direct Local Buffer Overflow
Posted Jul 8, 2010
Authored by chap0

GSM SIM Utility Direct RET local buffer overflow exploit. Affects version 5.15.

tags | exploit, overflow, local
SHA-256 | 15de76ced43372497ecbe7c41e888d3800c73d203ba85bdcf15a693b20d9e5a9
Hero DVD 3.0.8 Buffer Overflow
Posted Jul 8, 2010
Authored by chap0

Hero DVD version 3.0.8 remote buffer overflow exploit.

tags | exploit, remote, overflow
SHA-256 | b96ff541e105a651045d18859fd6f9197a4aa071b0a112c09f988427f6a709df
Citibank CitiDirect Online Banking Forced Use Of Vulnerable JRE
Posted Jul 8, 2010
Authored by Tomasz Tometzky Ostrowski

Citibank CitiDirect Online Banking software forces use of a vulnerable version of the Java Runtime Environment.

tags | advisory, java
SHA-256 | 8f04afa2c637e5b11d002f0ed54ab72e8d083fd6b496899eee91fea841cf853c
A Newbies Guide To The Underground Volume 2
Posted Jul 8, 2010
Authored by Ratdance, Aviator753, Killab, MLS577

Whitepaper called A Serious Newbie's Guide to the Underground v2. This is a continuation of ratdance's original Newbie's guide to the underground.

tags | paper
SHA-256 | 59bcdfa72ce194a61cb1c9f4dd3e108ef30765965712acfa60e17b5d35dd1d26
Go Null Yourself E-Zine Issue 01
Posted Jul 8, 2010
Authored by gny | Site gonullyourself.org

Go Null Yourself E-zine Issue 1 - Topics in this issue include RTLO Spoofing, Alternate Data Streams, Derandomizing Perl's RNG, Trojaning OpenSSH and more.

tags | trojan, perl, spoof, magazine
SHA-256 | da764bb263f3ff2f6073ba91670651cedf533d2c37e234ff11609dae96d20245
Qt 4.6.3 Denial Of Service
Posted Jul 8, 2010
Authored by Luigi Auriemma | Site aluigi.org

Qt versions 4.6.3 and below suffer from a remote denial of service vulnerability. Exploit included.

tags | exploit, remote, denial of service
SHA-256 | a98ad307a19189b74621d8afdcf89966c842795c15ee9ef0845f54e7ed9b8ae5
Simple Document Management System SQL Injection
Posted Jul 8, 2010
Authored by Sid3 effects

Simple Document Management System suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 88efa68c54a312c573492fcc24e9e0d04236ac16f5e0b750b8c02ebd0212eb7b
Joomla PaymentsPlus Blind SQL Injection
Posted Jul 8, 2010
Authored by Sid3 effects

The Joomla PaymentsPlus component suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 749208d402b089deb4c26f92d5aec10135bc3459acca84b3db501bafcc835522
Green Shop SQL Injection
Posted Jul 8, 2010
Authored by Ashiyane Digital Security Team

Green Shop suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 010cf2f6e59e0c8286863da323a89d1fb3a85282ad28083b5b525a50463d1791
Polymorphic Shellcode Generator For ARM Architecture
Posted Jul 8, 2010
Authored by Jonathan Salwan

This is a polymorphic shellcode generator for ARM architecture that produces execve("/bin/sh", ["/bin/sh"], NULL).

tags | shellcode
SHA-256 | de860077ea38ffa4a008b24122c4949fb3e19f8ebbc539c89d975eae3bc82105
Page 2 of 2
Back12Next

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    53 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close