<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Last 20</title>
	<link>http://packetstormsecurity.org/</link>
	<description>20 Most Recent Packet Storm File Additions</description>
	<language>en-us</language>

<item>
	<title>phpbb2plus-sql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/phpbb2plus-sql.txt</link>
	<description>phpBB2 Plus version 1.53 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>oraclexdb-overflow.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/oraclexdb-overflow.txt</link>
	<description>Oracle XDB FTP service UNLOCK buffer overflow exploit that spawns a reverse shell. </description>
</item>
<item>
	<title>phpnukerd-sql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/phpnukerd-sql.txt</link>
	<description>PHP-Nuke Ratedownload suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>ninkobb-addadmin.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/ninkobb-addadmin.txt</link>
	<description>NinkoBB version 1.3RC4 change / add administrator cross site request forgery exploit. </description>
</item>
<item>
	<title>joomlaalert-sql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/joomlaalert-sql.txt</link>
	<description>Joomla Alert suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>miranda-fail.txt</title>
	<link>http://packetstormsecurity.org/1003-advisories/miranda-fail.txt</link>
	<description>Miranda versions 0.8.16 and 0.9.0 alpha build #6 Unicode and SVN rev. 11383 suffer from a silent TLS failure. </description>
</item>
<item>
	<title>arp_sniff.c</title>
	<link>http://packetstormsecurity.org/1003-exploits/arp_sniff.c</link>
	<description>ARP Sniff (Sniffer Lite) is a tiny ARP sniffer. This tool will be useful to analyze the ARP packets in the network. The tool gives out two types of information, the 14 byte Ethernet header and 28 byte ARP header. The tool requires G++ compiler and a libpcap package. Three arguments are coded as of now. One is to list the available devices, second is to sniff the default device and third is to sniff the device given as argument. The sniffer outputs the Ethernet header (Source MAC address, Destination MAC address and Ethernet type), ARP Header (Hardware type, Protocol type, Hardware address length, Protocol address length, Opcode, Source Hardware address and Protocol address, Destination hardware address and Protocol address). </description>
</item>
<item>
	<title>varicad-overflow.c</title>
	<link>http://packetstormsecurity.org/1003-exploits/varicad-overflow.c</link>
	<description>VariCAD version 2010-2.05 EN local buffer overflow exploit. Comes with options to spawn calc.exe, bindshell, and add user shellcode. </description>
</item>
<item>
	<title>softsaurus-rfi.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/softsaurus-rfi.txt</link>
	<description>Softsaurus version 2.01 suffers from multiple remote file inclusion vulnerabilities. </description>
</item>
<item>
	<title>nensorcms-lfisql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/nensorcms-lfisql.txt</link>
	<description>Nensor CMS version 2.01 suffers from remote SQL injection and local file inclusion vulnerabilities. </description>
</item>
<item>
	<title>sahana-bypass.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/sahana-bypass.txt</link>
	<description>Sahana version 0.6.2.2 suffers from an authentication bypass vulnerability. </description>
</item>
<item>
	<title>USN-914-1.txt</title>
	<link>http://packetstormsecurity.org/1003-advisories/USN-914-1.txt</link>
	<description>Ubuntu Security Notice 914-1 - Mathias Krause discovered that the Linux kernel did not correctly handle missing ELF interpreters. Marcelo Tosatti discovered that the Linux kernel's hardware virtualization did not correctly handle reading the /dev/port special device. Sebastian Krahmer discovered that the Linux kernel did not correctly handle netlink connector messages. Ramon de Carvalho Valle discovered that the Linux kernel did not correctly validate certain memory migration calls. Jermome Marchand and Mikael Pettersson discovered that the Linux kernel did not correctly handle certain futex operations. </description>
</item>
<item>
	<title>secunia-qfxsrf.txt</title>
	<link>http://packetstormsecurity.org/1003-advisories/secunia-qfxsrf.txt</link>
	<description>Secunia Research has discovered a vulnerability in Quicksilver Forums, which can be exploited by malicious people to conduct cross-site request forgery attacks. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. execute arbitrary SQL queries by tricking a logged in administrator into visiting a malicious web site. </description>
</item>
<item>
	<title>joomlackforms-lfisql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/joomlackforms-lfisql.txt</link>
	<description>The Joomla Ckforms component suffers from local file inclusion and remote SQL injection vulnerabilities. </description>
</item>
<item>
	<title>preisschlact-sql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/preisschlact-sql.txt</link>
	<description>Preisschlacht Multi Liveshop System suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>sipwitch-0.7.4.tar.gz</title>
	<link>http://packetstormsecurity.org/sip/sipwitch-0.7.4.tar.gz</link>
	<description>GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP rver, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate.</description>
</item>
<item>
	<title>secunia-qfbidisclose.txt</title>
	<link>http://packetstormsecurity.org/1003-advisories/secunia-qfbidisclose.txt</link>
	<description>Secunia Research has discovered a security issue in Quicksilver Forums, which can be exploited by malicious people to disclose potentially sensitive information. The database backup functionality stores the database backup with a semi-predictable file name inside the web root. This can be exploited to download the backup by guessing the file name. </description>
</item>
<item>
	<title>postnukece-sql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/postnukece-sql.txt</link>
	<description>The Postnuke ContentExpress module suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>secunia-qfmddisclose.txt</title>
	<link>http://packetstormsecurity.org/1003-advisories/secunia-qfmddisclose.txt</link>
	<description>Secunia Research has discovered a security issue in Quicksilver Forums, which can be exploited by malicious, local users to disclose sensitive information. The application passes the database password via the command line to the  mysqldump  utility, which may disclose the password via the process list. </description>
</item>
<item>
	<title>joomlainclude-sql.txt</title>
	<link>http://packetstormsecurity.org/1003-exploits/joomlainclude-sql.txt</link>
	<description>The Joomla Include component suffers from a remote SQL injection vulnerability. </description>
</item></channel>
</rss>
