trust is easily compromised
Showing 101 - 125 of 17,531 RSS Feed

Remote Files

Ubuntu Security Notice USN-1434-1
Posted May 1, 2012
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1434-1 - Ivano Cristofolini discovered that Samba incorrectly handled some Local Security Authority (LSA) remote procedure calls (RPC). A remote, authenticated attacker could exploit this to grant administrative privileges to arbitrary users. The administrative privileges could be used to bypass permission checks performed by the Samba server.

tags | advisory, remote, arbitrary, local
systems | linux, ubuntu
advisories | CVE-2012-2111
MD5 | 38b127c8c765b97608e2d50fd59c5741
Red Hat Security Advisory 2012-0533-01
Posted May 1, 2012
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2012-0533-01 - Samba is an open-source implementation of the Server Message Block or Common Internet File System protocol, which allows PC-compatible machines to share files, printers, and other information. A flaw was found in the way Samba handled certain Local Security Authority Remote Procedure Calls. An authenticated user could use this flaw to issue an RPC call that would modify the privileges database on the Samba server, allowing them to steal the ownership of files and directories that are being shared by the Samba server, and create, delete, and modify user accounts, as well as other Samba server administration tasks.

tags | advisory, remote, local, protocol
systems | linux, redhat
advisories | CVE-2012-2111
MD5 | bb9a5704371e720d42b963106ef75117
PHP Volunteer Management 1.0.2 SQL Injection
Posted May 1, 2012
Authored by eidelweiss

PHP Volunteer Management version 1.0.2 suffers from a remote SQL injection vulnerability in get_messages.php.

tags | exploit, remote, php, sql injection
MD5 | 2417eddc3bf12db62df922d474f46cd9
Secunia Security Advisory 49008
Posted May 1, 2012
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in Remote-Anything, which can be exploited by malicious people to compromise a user's system.

tags | advisory, remote
MD5 | c19a364e383f28a17b9fcbf38ba1b6a9
McAfee Virtual Technician 6.3.0.1911 Code Execution
Posted Apr 30, 2012
Authored by rgod | Site retrogod.altervista.org

McAfee Virtual Technician version 6.3.0.1911 suffers from a MVT.MVTControl.6300 GetObject() active-x control security bypass remote code execution vulnerability.

tags | exploit, remote, code execution, activex
systems | linux
MD5 | fac7449425b40ef4af6501db05a9f65c
WebCalendar 1.2.4 Remote Code Execution
Posted Apr 30, 2012
Authored by EgiX

WebCalendar versions 1.2.4 and below suffer from a remote code execution vulnerability.

tags | exploit, remote, code execution
advisories | CVE-2012-1495, CVE-2012-1496
MD5 | 5f262ed03724a9203109c2bb48d3886f
PHP Volunteer Management 1.0.2 SQL Injection
Posted Apr 30, 2012
Authored by eidelweiss

PHP Volunteer Management version 1.0.2 suffers from a remote SQL injection vulnerability in get_messages.php.

tags | exploit, remote, php, sql injection
MD5 | 3e0f2910740ee66fc78fe170dce97825
Remote Anything Player 5.60.15 Denial Of Service
Posted Apr 30, 2012
Authored by Saint Patrick

Remote Anything Player version 5.60.15 suffers from a denial of service vulnerability.

tags | exploit, remote, denial of service
MD5 | 0b466556879a512ae2083fdf895e14c6
Booklight SQL Injection
Posted Apr 30, 2012
Authored by BHG Security Center, Nitrojen90

Booklight suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | f706b0a25ae1d26e10828d7e496245eb
Opial CMS 2.0 XSS / SQL Injection / Shell Upload
Posted Apr 29, 2012
Authored by the_storm | Site vulnerability-lab.com

Opial CMS version 2.0 suffers from cross site scripting, shell upload, and remote SQL injection vulnerabilities.

tags | exploit, remote, shell, vulnerability, xss, sql injection
MD5 | acccb552e07ec87ea83457bb160d54e8
China Pujiang Government SQL Injection
Posted Apr 29, 2012
Authored by Chokri Ben Achor | Site vulnerability-lab.com

The Chinese Pujiang government suffers from a remote blind SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 4aeb1073fd69f453d9ae641e2741a9e3
CMS GratingPeru S.A.C Cross Site Scripting / SQL Injection
Posted Apr 28, 2012
Authored by the_cyber_nuxbie

CMS GratingPeru S.A.C suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
MD5 | 8d7e011193836bbf70eb6fa57f91cb7b
Mandriva Linux Security Advisory 2012-066
Posted Apr 27, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-066 - Security issues were identified and fixed in Mozilla Firefox and Thunderbird. Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Using the Address Sanitizer tool, security researcher Aki Helin from OUSPG found that IDBKeyRange of indexedDB remains in the XPConnect hashtable instead of being unlinked before being destroyed. Using the Address Sanitizer tool, security researcher Atte Kettunen from OUSPG found a heap corruption in gfxImageSurface which allows for invalid frees and possible remote code execution. Anne van Kesteren of Opera Software found a multi-octet encoding issue where certain octets will destroy the following octets in the processing of some multibyte character sets. Various other issues were also addressed.

tags | advisory, remote, code execution
systems | linux, mandriva
advisories | CVE-2012-0468, CVE-2012-0467, CVE-2012-0469, CVE-2012-0470, CVE-2012-0471, CVE-2012-0472, CVE-2012-0473, CVE-2012-0474, CVE-2012-0477, CVE-2012-0478, CVE-2011-3062, CVE-2012-0479
MD5 | 2ded3927a0b08285a7c5a07703752ec9
eRealty Shop SQL Injection
Posted Apr 27, 2012
Authored by BHG Security Center

eRealty Shop suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 124cbc28812b9cfb5f098236f63908fe
Mandriva Linux Security Advisory 2012-065
Posted Apr 27, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-065 - The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service via a crafted application that uses a PDO driver for a fetch and then calls the session_start function, as demonstrated by a crash of the Apache HTTP Server. The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c. Insufficient validating of upload name leading to corrupted $_FILES indices. Various other issues have also been addressed.

tags | advisory, remote, web, denial of service, arbitrary, cgi, php, sql injection
systems | linux, mandriva
advisories | CVE-2012-0788, CVE-2012-0807, CVE-2012-0830, CVE-2012-0831, CVE-2012-1172
MD5 | d970a7f09cf0264c29f9c880d7bb0874
Uiga Personal Portal SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

Uiga Personal Portal suffers from a remote SQL injection vulnerability in index2.php.

tags | exploit, remote, php, sql injection
MD5 | e59c9c4630ed5fbfefbc54cc2684ef83
Uiga FanClub SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

Uiga FanClub suffers from a remote SQL injection vulnerability in index2.php.

tags | exploit, remote, php, sql injection
MD5 | e00972e95769968a93571b80baefac5a
theEZsite CMS SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

theEZsite CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 0cbe812f77b0274f93b0e1e102ded8fd
Source CMS SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

Source CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 828a7539bf9862345888c7a9781ba325
Yemen Ecommerce Technology SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

Yemen Ecommerce Technology suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 7493fc5d4cb52585e54849d03375bf08
WTE CMS SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

WTE CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | b50f529e57f515020666a0d329925ad1
WebData CMS SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

WebData CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 4eee8c5da02808f1fedc834e56ebc99f
Pinnacle Pixel CMS SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

Pinnacle Pixel CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 0761ae767e11130f18b66728eb923b4f
Joth CMS SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

Joth CMS suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 9d9329eb020c6f2c90218f0faa00d160
IrIran Shopping Script Blind SQL Injection
Posted Apr 27, 2012
Authored by Farbod Mahini

IrIran Shopping Script suffers from a remote blind SQL injection vulnerability in product.php.

tags | exploit, remote, php, sql injection
MD5 | 2a516164a47273d9d1bed4c821e4142c
Page 5 of 702
Back34567Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close