trust is easily compromised
Showing 1 - 25 of 430 RSS Feed

ASP Files

ASP-DEv XM Forums SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

ASP-DEv XM Forums suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
MD5 | 6cda01504d8352fc8ddac7396911d7c2
ASP-DEv XM Diary SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

ASP-DEv XM Diary suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
MD5 | 87a17c06069c18fea14aeb9b6a3d9968
LANDesk Lenovo ThinkManagement Console Remote Command Execution
Posted Apr 10, 2012
Authored by Andrea Micalizzi, juan vazquez | Site metasploit.com

This Metasploit module can be used to execute a payload on LANDesk Lenovo ThinkManagement Suite 9.0.2 and 9.0.3. The payload is uploaded as an ASP script by sending a specially crafted SOAP request to "/landesk/managementsuite/core/core.anonymous/ServerSetup.asmx" , via a "RunAMTCommand" operation with the command '-PutUpdateFileCore' as the argument. After execution, the ASP script with the payload is deleted by sending another specially crafted SOAP request to "WSVulnerabilityCore/VulCore.asmx" via a "SetTaskLogByFile" operation.

tags | exploit, asp
advisories | CVE-2012-1195, CVE-2012-1196, OSVDB-79276, OSVDB-79277
MD5 | 7e622d16202980709325aec7154b625c
Microsoft ASP.NET Forms Authentication Bypass
Posted Mar 29, 2012
Authored by K. Gudinavicius, m | Site sec-consult.com

Microsoft ASP.NET Forms versions 4.0.30319.237 and below suffer from an authentication bypass vulnerability.

tags | exploit, asp, bypass
advisories | CVE-2011-3416
MD5 | 74d23f9000afec3f9362934b375bf296
Secunia Security Advisory 48573
Posted Mar 28, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - demonalex has discovered some vulnerabilities in Matthew1471's ASP BlogX, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, vulnerability, xss, asp
MD5 | e1333098826e6fab5e9c93e8ac40cbab
Matthew1471s ASP BlogX Cross Site Scripting
Posted Mar 28, 2012
Authored by demonalex

Matthew1471s ASP BlogX suffers from a cross site scripting vulnerability.

tags | exploit, xss, asp
MD5 | 7a48064467650d2e09e193cc4f679e48
ASP Classifieds SQL Injection
Posted Mar 18, 2012
Authored by r45c4l

ASP Classifieds suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
MD5 | edef36f0f6aa7d25d54afe0253129e0e
Lastguru ASP Guestbook SQL Injection
Posted Mar 4, 2012
Authored by demonalex

Lastguru ASP Guestbook suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
MD5 | 744bf60db36981363e3fd5bea54deccf
Acidcat ASP CMS 3.5.2 Cross Site Scripting
Posted Jan 21, 2012
Authored by d3v1l, RandomStorm

Acidcat ASP CMS versions 3.5.1 and 3.5.2 suffer from multiple cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, asp
MD5 | b9690e647db54a97c35231a0971ed3df
ASP.NET Hash Denial Of Service Payload
Posted Jan 6, 2012
Authored by HybrisDisaster

ASP.NET hash denial of service exploit payload. Includes 1mb and 4mb files.

tags | exploit, denial of service, asp
systems | unix
MD5 | 33963c2fd6e029d6ca3d72771e9086b2
Microsoft ASP.NET Forms Authentication Bypass
Posted Dec 30, 2011
Authored by K. Gudinavicius | Site sec-consult.com

Microsoft ASP.NET Forms suffers from a null byte termination authentication bypass vulnerability that exists in the CopyStringToUnAlingnedBuffer() function of the webengine4.dll library used by the .NET framework. The unicode string length is determined using the lstrlenW function. The lstrlenW function returns the length of the string, in characters not including the terminating null character. If the unicode string containing a null byte is passed, its length is incorrectly calculated, so only characters before the null byte are copied into the buffer.

tags | advisory, asp, bypass
advisories | CVE-2011-3416
MD5 | 63981257663cd145e7371de1db9fbfbe
Zero Day Initiative Advisory 11-354
Posted Dec 22, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-354 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Managed Printing Administration. Authentication is not required to exploit this vulnerability. There multiple classes of flaws within this product including arbitrary file creation, null char truncation and directory traversal. Null injection and directory traversal can be used in the form data passed to \Inetpub\wwwroot\hpmpa\jobDelivery\Default.asp to remotely create arbitrary files.

tags | advisory, remote, arbitrary, asp
advisories | CVE-2011-4168
MD5 | 8d0d075c9270d3ca27e4079e36cc1eaf
Zero Day Initiative Advisory 11-353
Posted Dec 22, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-353 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Managed Printing Administration. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MPAUploader.dll file. An extended length string can be passed into scripts within the management website on port 80 (the 'uploadfile' multipart form data 'filename' parameter in Default.asp) and ultimately to MPAUploader.dll. As a static stack allocation is used to store the buffer and the string length is not handled properly, a remote attacker may overwrite the stack and ultimately execute remote code.

tags | advisory, remote, arbitrary, asp
advisories | CVE-2011-4167
MD5 | 671ebea656ba9bc4875b4c9cf481f2dc
QuesCom Qportal User 5.10.014 Source Disclosure
Posted Dec 9, 2011
Authored by Ewerson Guimaraes | Site dclabs.com.br

QueCom Qortal User version 5.10.014 suffers from an ASP source code disclosure vulnerability.

tags | exploit, asp
MD5 | d21d86512983c85718ce610afe65071e
Secunia Security Advisory 46686
Posted Nov 2, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in VP-ASP, which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, sql injection, asp
MD5 | 136cda02af0bcb0e0d8959fb90aaecb6
Asp Basit Haber Script 1.0 SQL Injection
Posted Sep 19, 2011
Authored by m3rciL3Ss

Asp Basit Haber Script version 1.0 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
MD5 | f6145c18d08b80d5a81abc4f85e235bd
Planeteria Design ASP SQL Injection
Posted Aug 25, 2011
Authored by tempe_mendoan

Planeteria Design ASP suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
MD5 | f53787bb93013f57794e5df91ab50661
Secunia Security Advisory 45661
Posted Aug 23, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - L0rd CrusAd3r has reported two vulnerabilities in CodeWidgets.com Pop-Over Login Form (ASP), which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, vulnerability, sql injection, asp
MD5 | 34e1691c3bf8815c79e07b840a0916ef
Magnon Solutions ASP SQL Injection
Posted Aug 23, 2011
Authored by kebumen cyber

Magnon Solutions ASP suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection, asp
MD5 | a0564b5e944f33b5bbca3dd3433a0adb
Secunia Security Advisory 45619
Posted Aug 20, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two vulnerabilities have been reported in Multiple Question - Multiple Choice Online Questionaire (ASP), which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, vulnerability, sql injection, asp
MD5 | 5a85609dfda0a79839c139c6b2c3d1bf
Secunia Security Advisory 45625
Posted Aug 16, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in Aipo and Aipo ASP, which can be exploited by malicious users to conduct SQL injection attacks.

tags | advisory, sql injection, asp
MD5 | e88e8dc1f587d92c50d27afea438386b
Virtual Consultant SQL Injection
Posted Jul 26, 2011
Authored by CriminalCoder

Virtual Consultant suffers from a remote SQL injection vulnerability in newsDetail.asp.

tags | exploit, remote, sql injection, asp
MD5 | 95bc5ae5b05384e27fc56f5968f1c9cf
EMC SourceOne ASP.NET Application Tracing Information Disclosure
Posted May 17, 2011
Site emc.com

EMC SourceOne Email Management may allow the disclosure of application-sensitive information using ASP.NET Application Tracing. The ASP.NET application trace is enabled in affected versions of EMC SourceOne Email Management. This trace file may contain application-sensitive information that can be accessed by a remote user. Authentication is required to access the trace file.

tags | advisory, remote, asp
advisories | CVE-2011-1424
MD5 | 52b444d82597464cd41c6e1c5a2e352d
Uploadform ASP Script Shell Upload
Posted Apr 14, 2011
Authored by Net.Edit0r

The Uploadform ASP script suffers from a shell upload vulnerability.

tags | exploit, shell, asp
MD5 | 6e89d47c37f5dc058220f8cb481bf813
Ideas Factory PHP / ASP SQL Injection
Posted Apr 3, 2011
Authored by eXeSoul

Ideas Factory PHP and ASP suffers from a remote SQL injection vulnerability.

tags | exploit, remote, php, sql injection, asp
MD5 | a919ad0d6f018b22ff81ee9dd28b9a7f
Page 1 of 18
Back12345Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close