Section: .. / 0601-exploits /
| /// File Name: |
simpleBlog21.txt |
Description:
|
SimpleBlog version 2.1 is susceptible to SQL injection and cross site scripting attacks due to a lack of variable sanitization.
| | Author: | Zinho | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1213 | | Last Modified: | Jan 15 18:27:07 2006 |
| MD5 Checksum: | 40c9f202077dfc69e005da9b100dd50e |
|
| /// File Name: |
hsphereXSS.txt |
Description:
|
H-Sphere versions 2.4.3 Patch 8 and below suffer from a cross site scripting vulnerability.
| | Author: | M.Neset KABAKLI | | Homepage: | http://www.wakiza.com | | File Size: | 1206 | | Last Modified: | Jan 15 17:03:42 2006 |
| MD5 Checksum: | 9bc330c668318d624534c154cf2552f5 |
|
| /// File Name: |
EV0022.txt |
Description:
|
MyPhPim version 01.05 is susceptible to cross site scripting and SQL injection vulnerabilities. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1201 | | Last Modified: | Jan 15 02:35:55 2006 |
| MD5 Checksum: | b65c15eaae35191db1b602732629f8b7 |
|
| /// File Name: |
WebspotBlogging.txt |
Description:
|
WebspotBlogging v3.0 suffers from SQL injection due to improper input sanitization. POC included.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com | | File Size: | 1200 | | Last Modified: | Jan 25 09:13:29 2006 |
| MD5 Checksum: | ffbbb0a988c82b4301c83de6e0777cde |
|
| /// File Name: |
EV0010.txt |
Description:
|
B-net Software version 1.0 is susceptible to cross site scripting attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1185 | | Last Modified: | Jan 4 06:09:07 2006 |
| MD5 Checksum: | 8e8f514602094834d3eb15a736e18fff |
|
| /// File Name: |
eggblog-sql.txt |
Description:
|
eggblog v2.0 is vulnerable to XSS and SQL injection.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1177 | | Last Modified: | Jan 25 08:51:02 2006 |
| MD5 Checksum: | e06afd90aa34dde57e03d9993b8c3647 |
|
| /// File Name: |
pixelpostXSS.txt |
Description:
|
Pixelpost version 1.4.3 is susceptible to cross site scripting attacks.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1173 | | Last Modified: | Jan 29 22:38:06 2006 |
| MD5 Checksum: | 04ad864d958b3c22eb2c159e70813772 |
|
| /// File Name: |
EV0011.txt |
Description:
|
ScozBook version BETA 1.1 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1154 | | Last Modified: | Jan 4 06:09:45 2006 |
| MD5 Checksum: | b44ed22d773155b59a9f51328ccdc751 |
|
| /// File Name: |
ExpressionEngine-1.4.1.txt |
Description:
|
ExpressionEngine 1.4.1 does not sanatize the HTTP_REFERER variable. This can be used to post HTTP query with fake Referrer value which may contain arbitrary html or script code. This code will be executed when administrator(or any user) will open Referrer Statistics.
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/vulns/48/summary.html | | File Size: | 1137 | | Last Modified: | Jan 26 11:16:04 2006 |
| MD5 Checksum: | de8a40d525006723af46d5ab925d4feb |
|
| /// File Name: |
EV0016.txt |
Description:
|
Proyecto Domus version 2.10 is susceptible to a cross site scripting vulnerability. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1127 | | Last Modified: | Jan 8 06:30:18 2006 |
| MD5 Checksum: | afec9a648f52c5327ffda04fcbe5ce4e |
|
| /// File Name: |
adv20060116.txt |
Description:
|
phpXplorer version 0.9.33 is susceptible to a classic directory traversal attack.
| | Author: | Oriol Torrent Santiago | | File Size: | 1100 | | Last Modified: | Jan 22 00:52:49 2006 |
| MD5 Checksum: | 9409f34c07ef0adb602d6742c40dbcc0 |
|
| /// File Name: |
EV0004.txt |
Description:
|
Chipmunk Guestbook versions 1.4 and below suffer from a cross site scripting flaw. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1079 | | Last Modified: | Jan 4 05:37:03 2006 |
| MD5 Checksum: | 428b07a8f3feee943c2022a41e2dc2f8 |
|
| /// File Name: |
EV0029.txt |
Description:
|
Light Weight Calendar version 1.0 is susceptible to remote php code execution. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1071 | | Last Modified: | Jan 21 07:18:17 2006 |
| MD5 Checksum: | 3953cd22bff9935a5f9a96a0d6bc6969 |
|
| /// File Name: |
EV0024.txt |
Description:
|
CaLogic Calendars version 1.2.2 is susceptible to cross site scripting attacks.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1070 | | Last Modified: | Jan 22 01:04:38 2006 |
| MD5 Checksum: | a34ce177aa9b5e8a5a00d098a66db7b2 |
|
| /// File Name: |
EV0031.txt |
Description:
|
Bit 5 Blog version 8.01 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1057 | | Last Modified: | Jan 21 22:07:49 2006 |
| MD5 Checksum: | 66d8fcf4a63578928449c544f89f0c8e |
|
| /// File Name: |
EV0026.txt |
Description:
|
TankLogger version 2.4 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1048 | | Last Modified: | Jan 15 17:34:48 2006 |
| MD5 Checksum: | 1a254764515ad09d8c965a402d714a6d |
|
| /// File Name: |
ezDatabase20.txt |
Description:
|
ezDatabase versions 2.0 and below are susceptible to remote php file inclusion flaws due to a lack of sanitizing variables.
| | Author: | Pridels Team | | Homepage: | http://pridels.blogspot.com | | File Size: | 1047 | | Last Modified: | Jan 15 18:19:30 2006 |
| MD5 Checksum: | b063abadc38f3993016c8b7fed112f70 |
|
| /// File Name: |
EV0021.txt |
Description:
|
Venom Board version 1.22 is susceptible to SQL injection attacks. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1039 | | Last Modified: | Jan 10 05:58:19 2006 |
| MD5 Checksum: | 0595dd1c491f271032a218697aae24b9 |
|
| /// File Name: |
EV0005.txt |
Description:
|
PHPenpals version 310704 suffers from a SQL injection flaw in profile.php. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1036 | | Last Modified: | Jan 4 05:38:16 2006 |
| MD5 Checksum: | 6f79885444231de57267c05ea2925576 |
|
| /// File Name: |
EV0009.txt |
Description:
|
PHPjournaler version 1.0 is susceptible to SQL injection attacks via index.php. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 1021 | | Last Modified: | Jan 4 05:41:21 2006 |
| MD5 Checksum: | ba8cd3f4d615b26d13a8ea614dcca1e6 |
|
| /// File Name: |
MiniNukeSQL.txt |
Description:
|
MiniNuke CMS System versions 1.8.2 and below suffer from a SQL injection attack in news.asp.
| | Author: | nukedx | | Homepage: | http://www.nukedx.com | | File Size: | 1014 | | Last Modified: | Jan 15 17:59:57 2006 |
| MD5 Checksum: | 68d24208b9496fa63148b8e47e2ce704 |
|
| /// File Name: |
EV0027.txt |
Description:
|
Wordcircle version 2.17 is susceptible to SQL injection attacks that allows for authentication bypass. Exploitation details provided.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 989 | | Last Modified: | Jan 15 17:35:41 2006 |
| MD5 Checksum: | 142aa49c577d9d8aa7f1872cd3e41d41 |
|
|
|
|
|