you are connected
Showing 1 - 25 of 26,914 RSS Feed

Exploit Files

Gekko CMS File Disclosure
Posted May 25, 2012
Authored by L3b-r1'z

Gekko CMS appears to suffer from a file disclosure vulnerability.

tags | exploit, info disclosure
MD5 | fc10d007f192d991f48cc9832fb49312
WeBid converter.php Remote PHP Code Injection
Posted May 25, 2012
Authored by EgiX, juan vazquez | Site metasploit.com

This Metasploit module exploits a vulnerability found in WeBid version 1.0.2. By abusing the converter.php file, a malicious user can inject PHP code in the includes/currencies.php script without any authentication, which results in arbitrary code execution.

tags | exploit, arbitrary, php, code execution
advisories | OSVDB-73609
MD5 | 8dc19f398388284a81cf2ecae5005436
RabidHamster R4 Log Entry sprintf() Buffer Overflow
Posted May 25, 2012
Authored by Luigi Auriemma, sinn3r | Site metasploit.com

This Metasploit module exploits a vulnerability found in RabidHamster R4's web server. By supplying a malformed HTTP request, it is possible to trigger a stack-based buffer overflow when generating a log, which may result in arbitrary code execution under the context of the user.

tags | exploit, web, overflow, arbitrary, code execution
advisories | OSVDB-79007
MD5 | d5c7b728cc34e438d56471e6fbda49bd
ResEdit 1.5.11-win32 Buffer Overflow
Posted May 25, 2012
Authored by Walied Assar

ResEdit version 1.5.11-win32 suffers from a buffer overflow. Proof of concept denial of service exploits included.

tags | exploit, denial of service, overflow, proof of concept
systems | linux, windows
MD5 | 6f23782d3add86957f122b199a5849ec
DornCMS 1.4 (add_page.php) Arbitrary File Upload
Posted May 25, 2012
Authored by KedAns-Dz | Site metasploit.com

This Metasploit module exploits a vulnerability found in Dorn Content Management Script (CMS), version 1.4. By abusing the add_page.php file, the attacker can upload/add a new file (.php) to the /cms/pages/ directory without any authentication, which results in arbitrary code execution.

tags | exploit, arbitrary, php, code execution
MD5 | c93d65487a1c0efc12fc9a8a68adc5db
LogAnalyzer 3.4.2 Cross Site Scripting / SQL Injection / File Read
Posted May 25, 2012
Authored by Filippo Cavallarin

LogAnalyzer version 3.4.2 suffers from cross site scripting, arbitrary file reading, and remote SQL injection vulnerabilities.

tags | exploit, remote, arbitrary, vulnerability, xss, sql injection
MD5 | 2427d2cf98e92db38be0f21c58da1065
Pligg CMS 1.2.1 Cross Site Scripting / Local File Inclusion
Posted May 25, 2012
Authored by High-Tech Bridge SA | Site htbridge.ch

Pligg CMS version 1.2.1 suffers from cross site scripting and local file inclusion vulnerabilities.

tags | exploit, local, vulnerability, xss, file inclusion
advisories | CVE-2012-2435, CVE-2012-2436
MD5 | 7b79d17eacb9df80bafc88ab8fbbdabc
pragmaMx 1.12.1 Cross Site Scripting
Posted May 25, 2012
Authored by High-Tech Bridge SA | Site htbridge.ch

pragmaMx version 1.12.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2012-2452
MD5 | 5433c6278bfe6b6212f911b0a46eda42
DynPage 1.0 Cross Site Request Forgery / Shell Upload
Posted May 25, 2012
Authored by KedAns-Dz

DynPage version 1.0 suffers from cross site request forgery and shell upload vulnerabilities.

tags | exploit, shell, vulnerability, csrf
MD5 | 476adc1bf90918f7ad3741caca2d770e
Social Engine 4.2.2 Cross Site Request Forgery / Cross Site Scripting
Posted May 24, 2012
Authored by Tiago Natel de Moura

Social Engine version 4.2.2 suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | exploit, vulnerability, xss, csrf
advisories | CVE-2012-2216
MD5 | 46affb7ec997a27515c12a50d78d65f6
Wireshark DIAMETER Denial Of Service
Posted May 24, 2012
Authored by Wireshark

Wireshark versions 1.4.0 through 1.4.12 and 1.6.0 through 1.6.7 suffer from a DIAMETER dissector denial of service vulnerability.

tags | exploit, denial of service
systems | linux
MD5 | d94ce6017c8d48224a7a09c0a77c7c0e
Wireshark Dissector Denial Of Service
Posted May 24, 2012
Authored by Laurent Butti

Wireshark versions 1.6.0 through 1.6.7 and versions 1.4.0 through 1.4.12 suffer from multiple dissector related denial of service vulnerabilities.

tags | exploit, denial of service, vulnerability
systems | linux
MD5 | b69533c3c9d8a81ed6f166ce32f3088d
Wireshark Misaligned Memory Denial Of Service
Posted May 24, 2012
Authored by Klaus Heckelmann

Wireshark versions 1.6.0 through 1.6.7 and versions 1.4.0 through 1.4.12 suffer from a misaligned memory denial of service vulnerability.

tags | exploit, denial of service
systems | linux
advisories | CVE-2012-2394
MD5 | e44a652926a9f450c49f6ecbc1a0cd3c
Jaow 2.4.5 Blind SQL Injection
Posted May 24, 2012
Authored by kallimero

Jaow versions 2.4.5 and below suffer from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 6e6b513afde6050a95045e553840c8c1
bsnes 0.87 Denial Of Service
Posted May 24, 2012
Authored by Pr0T3cT10n

bsnes version 0.87 suffers from a denial of service vulnerability.

tags | exploit, denial of service
MD5 | e1b422d8ffa4c0e558e83d2d33d761f7
OpenOffice OLE Importer DocumentSummaryInformation Stream Handling Overflow
Posted May 24, 2012
Site metasploit.com

This Metasploit module exploits a vulnerability in OpenOffice 2.3.1 and 2.3.0 on Microsoft Windows XP SP3. By supplying a OLE file with a malformed DocumentSummaryInformation stream, an attacker can gain control of the execution flow, which results arbitrary code execution under the context of the user.

tags | exploit, arbitrary, code execution
systems | windows, xp
advisories | CVE-2008-0320, OSVDB-44472
MD5 | c768b9282de90ed20180d7ae12452941
appRain CMF Arbitrary PHP File Upload Vulnerability
Posted May 24, 2012
Authored by EgiX, sinn3r | Site metasploit.com

This Metasploit module exploits a vulnerability found in appRain's Content Management Framework (CMF), version 0.1.5 or less. By abusing the uploadify.php file, a malicious user can upload a file to the uploads/ directory without any authentication, which results in arbitrary code execution.

tags | exploit, arbitrary, php, code execution
advisories | CVE-2012-1153, OSVDB-78473
MD5 | 326c66024ed2135e3da4e6dab3059464
PHPCollab 2.5 Unauthenticated Access
Posted May 23, 2012
Authored by team ' and 1=1--

PHPCollab version 2.5 fails to properly block access to data on the system.

tags | exploit, bypass
MD5 | bc86a1653dea13519ffa3cf29b1445e8
YDFramework 2.0-Beta1 File Disclosure
Posted May 23, 2012
Authored by L3b-r1'z

YDFramework version 2.0-Beta1 suffers from a local file disclosure vulnerability.

tags | exploit, local, info disclosure
MD5 | 2e0a865b7df93b06e07bffc87eb32d85
Mod_Auth_OpenID Session Stealing
Posted May 23, 2012
Authored by Peter Ellehauge

mod_auth_openid versions prior to 0.7 insecurely store session ids in /tmp/mod_auth_openid.db unencrypted.

tags | exploit
advisories | CVE-2012-2760
MD5 | e87cd3eab63295cb00d55e62f346bb6c
Symantec End Point Protection / Network Access Control 11.x Code Execution
Posted May 23, 2012
Authored by 41.w4r10r

Symantec End Point Protection version 11.x and Symantec Network Access Control version 11.x local code execution proof of concept exploit.

tags | exploit, local, code execution, proof of concept
advisories | CVE-2012-0289
MD5 | 174fc0f373ce2fdf3dc6f1c8d79bb041
PHPCollab 2.5 Unauthenticated File Upload
Posted May 23, 2012
Authored by team ' and 1=1--

PHPCollab version 2.5 suffers from an unauthenticated file upload vulnerability.

tags | exploit, file upload
MD5 | 1b7459efe1a8274c10aa92fb7e82792b
Ajaxmint Gallery 1.0 Local File Inclusion
Posted May 23, 2012
Authored by Akastep

Ajaxmint Gallery version 1.0 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
MD5 | db4ac715f286ea13414831d16f447d95
RuubikCMS 1.1.0 Beta XSS / Disclosure / Directory Traversal
Posted May 23, 2012
Authored by Akastep

RuubikCMS version 1.1.0 Beta suffers from cross site scripting, information disclosure, and directory traversal vulnerabilities.

tags | exploit, vulnerability, xss, file inclusion, info disclosure
MD5 | dbca1c445b9b9049982dc2e17c9a37be
Novell Client 4.91 SP3/4 Privilege Escalation
Posted May 23, 2012
Authored by sickness

Novell Client version 4.91 SP3/4 privilege escalation exploit for Win2K3 and WinXP.

tags | exploit
systems | windows, xp
advisories | CVE-2007-5762
MD5 | e59e74f4b1cab13f13403229646f8b01
Page 1 of 1,077
Back12345Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close