Section: .. / 0512-exploits /
| /// File Name: |
ag22sql.txt |
Description:
|
Advanced Guestbook version 2.2 suffers from a SQL injection flaw in the username variable. The SQL injection flaw for the password variable was discovered for this same version back in April of 2004.
| | Author: | BHST | | Related Exploit: | advguest.txt | | File Size: | 785 | | Last Modified: | Dec 26 13:50:00 2005 |
| MD5 Checksum: | 3cc8c772fdccc7a409005cb7a75c6eef |
|
| /// File Name: |
hcXSS.txt |
Description:
|
Hosting Controller is susceptible to cross site scripting attacks.
| | Author: | Lone Rider Knight | | File Size: | 1653 | | Last Modified: | Dec 26 13:45:23 2005 |
| MD5 Checksum: | 8e45f9ca208630c7be0dfc41bab14e57 |
|
| /// File Name: |
marmaraXSS.txt |
Description:
|
MarmaraWeb E-Commerce is susceptible to cross site scripting attacks.
| | Author: | B3g0k | | File Size: | 776 | | Last Modified: | Dec 18 04:22:54 2005 |
| MD5 Checksum: | 6a87dd144224dd7bbac2d3717dbf2432 |
|
| /// File Name: |
limbo1042_xpl.txt |
Description:
|
LIMBO CMS versions 1.0.4.2 and below suffer from blind SQL injection, cross site scripting, local file inclusion, remote code execution, and other fun flaws. Exploit provided.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org/ | | File Size: | 12178 | | Last Modified: | Dec 15 01:56:37 2005 |
| MD5 Checksum: | 7ffea299a93e6527c9cced8875eb9513 |
|
| /// File Name: |
ibm_css.txt |
Description:
|
IBM Websphere 6 sample scripts are susceptible to cross site scripting vulnerabilities. Details provided.
| | Author: | dr_insane | | File Size: | 3434 | | Last Modified: | Dec 15 01:46:47 2005 |
| MD5 Checksum: | 6db36956f39a0952c9aaccb6b92359ef |
|
| /// File Name: |
MS05-053.c |
Description:
|
Microsoft Windows Metafile (WMF) remote exploit which takes advantage of the bug known as ms05-053. This program creates a special .wmf file which crashes IE by overflowing the "mtNoObjects" header.
| | Author: | Winny Thomas | | File Size: | 4821 | | Last Modified: | Dec 14 05:12:31 2005 |
| MD5 Checksum: | 380f01f84a68f99123f0eaeefe547cc1 |
|
| /// File Name: |
openview_connectednodes_exec.pm.txt |
Description:
|
This Metasploit module exploits an arbitrary command execution vulnerability in the HP OpenView connectedNodes.ovpl CGI application. The results of the command will not be displayed to the screen.
| | Author: | Valerio Tesei | | File Size: | 2731 | | Related OSVDB(s): | 19057 | | Related CVE(s): | CVE-2005-2773 | | Last Modified: | Dec 14 03:26:31 2005 |
| MD5 Checksum: | ae5ae0d62af26ea683bce8a720fc56eb |
|
| /// File Name: |
oracle9i_xdb_http.pm.txt |
Description:
|
This Metasploit module exploits a stack overflow in the authorization code of the Oracle 9i HTTP XDB service.
| | Author: | y0 | | File Size: | 4118 | | Last Modified: | Dec 14 03:23:36 2005 |
| MD5 Checksum: | 3904180db4222415f801532251f226a4 |
|
| /// File Name: |
fireburn.txt |
Description:
|
Proof of concept exploit for Firefox 1.0.4 for the InstallVersion.compareTo() vulnerability. Needs functional shellcode to work.
| | Author: | Aviv Raff | | Homepage: | http://aviv.raffon.net/ | | File Size: | 2912 | | Last Modified: | Dec 14 03:18:31 2005 |
| MD5 Checksum: | a7b9197c7c69f746d4d5c68ef60627c1 |
|
| /// File Name: |
adpHashdisclose.txt |
Description:
|
ADP Forum versions 2.0 through 2.0.3 suffers from a direct download flaw that discloses users' password hashes.
| | Author: | Liz0ziM | | Homepage: | http://www.biyo.tk | | File Size: | 1194 | | Last Modified: | Dec 14 03:01:51 2005 |
| MD5 Checksum: | 3a4537af165b9812a28f6030875fd239 |
|
| /// File Name: |
BTGrup.txt |
Description:
|
The BTGrup Admin WebController script is susceptible to a SQL injection attack.
| | Author: | khc | | File Size: | 172 | | Last Modified: | Dec 14 02:27:50 2005 |
| MD5 Checksum: | b077a1a5be54dbc0ddd5f2155b17801d |
|
| /// File Name: |
imoelPassword.txt |
Description:
|
Direct download access of the setting.php file in IMOEL CMS allows for disclosure of the SQL password.
| | Author: | mehrtash mallahzadeh | | Homepage: | http://www.ashiyane.com | | File Size: | 647 | | Last Modified: | Dec 14 02:26:57 2005 |
| MD5 Checksum: | c3cf39d735cdc657ca8f40d348f2d188 |
|
| /// File Name: |
SEC-20051211-0.txt |
Description:
|
SEC-CONSULT Security Advisory 20051211-0 - Horde versions 3.0.7 and below, Kronolith versions 2.0.5 and below, Mnemo version 2.0.2 and below, Nag versions 2.0.3 and below, and Turba versions 2.0.4 and below are susceptible to cross site scripting attacks.
| | Author: | Johannes Greil | | Homepage: | http://www.sec-consult.com | | File Size: | 8439 | | Last Modified: | Dec 14 02:16:06 2005 |
| MD5 Checksum: | cd3e50c6d30cf26aab9c6ebd6280f69c |
|
| /// File Name: |
arabPortalSQL.txt |
Description:
|
Arab Portal System version 2 Beta 2 is susceptible to SQL injection attacks.
| | Author: | Devil-00 | | File Size: | 2062 | | Last Modified: | Dec 14 02:12:40 2005 |
| MD5 Checksum: | fb558b6b1217c312052d18162d60388d |
|
| /// File Name: |
mkportalXSS.txt |
Description:
|
MkPortal with smf forum is susceptible to a cross site scripting flaw.
| | Author: | spyMASter | | Homepage: | http://www.cyber-warrior.org | | File Size: | 508 | | Last Modified: | Dec 14 02:07:06 2005 |
| MD5 Checksum: | 5977b955d1a3623fe302409883dcd8eb |
|
| /// File Name: |
Bb_6.zip |
Description:
|
Blackboard versions 6.3.1.424 and 6.2.3.23 (and possibly earlier versions) are susceptible to login bypass, spoofing of announcements, and proxying flaws.
| | Author: | dr_insane | | File Size: | 13454 | | Last Modified: | Dec 14 01:36:44 2005 |
| MD5 Checksum: | 7113f857a7b23c9e90395e557919c2c2 |
|
| /// File Name: |
flatnuke256_xpl.txt |
Description:
|
Flatnuke version 2.5.6 privilege escalation and remote command execution exploit.
| | Author: | rgod | | Homepage: | http://retrogod.altervista.org | | File Size: | 12931 | | Last Modified: | Dec 14 01:31:26 2005 |
| MD5 Checksum: | 0b914d4061a58677e535436986fc8701 |
|
| /// File Name: |
SMF11SQL.txt |
Description:
|
Simple Machines Forum version 1.1 rc1 is susceptible to SQL injection attacks.
| | Author: | trueend5 | | Homepage: | http://www.KAPDA.ir | | File Size: | 2037 | | Last Modified: | Dec 14 01:18:45 2005 |
| MD5 Checksum: | d419208a5047a55cc6a819f041e3c940 |
|
|
|
|
|