Section: .. / 0701-exploits /
| /// File Name: |
MOAB-09-01-2007.rb.txt |
Description:
|
Month of Apple Bugs - Exploit for a vulnerability in Finder. Finder is affected by a memory corruption vulnerability, which leads to an exploitable denial of service condition and potential arbitrary code execution, that can be triggered by DMG images. One of two exploits.
| | Author: | LMH | | Homepage: | http://projects.info-pull.com/moab/index.html | | Related Exploit: | MOAB-09-01-2007.dmg | | File Size: | 668 | | Last Modified: | Jan 13 17:45:07 2007 |
| MD5 Checksum: | 7c18ab0283bcd54f3690d40678de850b |
|
| /// File Name: |
exploit-of-the-apes.rb.txt |
Description:
|
Month of Apple Bugs - Exploit for the Application Enhancer (APE), which is affected by a local privilege escalation vulnerability that allows local users to gain root privileges.
| | Author: | LMH, Johnny Pwnerseed | | Homepage: | http://projects.info-pull.com/moab/index.html | | File Size: | 2812 | | Last Modified: | Jan 13 17:43:30 2007 |
| MD5 Checksum: | ba29c0afc8360ed6c048e0ad74fcdca5 |
|
| /// File Name: |
MOAB-07-01-2007.html |
Description:
|
Month of Apple Bugs - This HTML file is an exploit for OmniWeb. OmniWeb is affected by a format string vulnerability in the handling of Javascript alert() function, which could allow remote arbitrary code execution.
| | Author: | LMH, Kevin Finisterre | | Homepage: | http://projects.info-pull.com/moab/index.html | | File Size: | 421 | | Last Modified: | Jan 13 17:41:21 2007 |
| MD5 Checksum: | 47bf65470e57cbcf70bc69bb1157e73f |
|
| /// File Name: |
MOAB-06-01-2007.pdf |
Description:
|
Month of Apple Bugs - Warning, this pdf is an exploit. The current PDF specification is affected by a design flaw, a rogue Pages entry or malicious catalog dictionary could cause a denial of service (memory corruption condition, memory leakage, etc) or potential arbitrary code execution in the reader application.
| | Author: | LMH, Kevin Finisterre | | Homepage: | http://projects.info-pull.com/moab/index.html | | File Size: | 4026 | | Last Modified: | Jan 13 17:40:09 2007 |
| MD5 Checksum: | 525a1a163dab2a135fb38b6bf1510f4d |
|
| /// File Name: |
critical_openbsd_communism.c |
Description:
|
Critical Security OpenBSD 3.x through 4.0 vga_ioctl() local root exploit.
| | Homepage: | http://www.critical.lt/ | | File Size: | 3541 | | Last Modified: | Jan 13 17:29:28 2007 |
| MD5 Checksum: | e0ffac6fd11b9f41e12b3acbdde329a8 |
|
| /// File Name: |
mpsw-rfi.txt |
Description:
|
The Magic Photo Storage website suffers from a remote file inclusion vulnerability.
| | Author: | k1tk4t | | File Size: | 1406 | | Last Modified: | Jan 13 16:57:30 2007 |
| MD5 Checksum: | c874f011c71475bc4ea69e02693e9658 |
|
| /// File Name: |
tk53-advisory-1.txt |
Description:
|
CenterICQ contains support for LiveJournal (http://www.livejournal.com/), such as posting to your own blog, reading other blogs' RSS feeds, and other community-related functions, such as showing whether a user has added or removed your own users to/from the friend list, all via a unified HTTP interface provided by LiveJournal. The latter functionality is vulnerable to a buffer overflow and possible remote code execution. Affected versions range from 4.9.11 through 4.21.0. Proof of concept exploit included.
| | Author: | Lolek, Roflek | | File Size: | 7884 | | Last Modified: | Jan 13 16:39:18 2007 |
| MD5 Checksum: | b01fc1a5c2ddaf95af63ac9ace7db750 |
|
| /// File Name: |
camouflage-crack.txt |
Description:
|
Camouflage version 1.2.1 suffers from a vulnerability that allows access to encrypted files.
| | Author: | NtWaK0, NoPh0BiA | | File Size: | 4126 | | Last Modified: | Jan 13 16:37:12 2007 |
| MD5 Checksum: | e55cf76cf98831630e2554aa141c3efd |
|
| /// File Name: |
geobb-rfi.txt |
Description:
|
GeoBB Georgian Bulletin Board suffers from a remote file inclusion vulnerability.
| | Author: | ShaFuq31 | | File Size: | 430 | | Last Modified: | Jan 13 16:33:32 2007 |
| MD5 Checksum: | b359504a873aa517fd54397e5482b634 |
|
| /// File Name: |
dayfox-rfi.txt |
Description:
|
Dayfox Blog suffers from a remote file inclusion vulnerability.
| | Author: | ShaFuq31 | | File Size: | 484 | | Last Modified: | Jan 13 16:32:45 2007 |
| MD5 Checksum: | f4f5d0c3f2bb0e73b77feaedcc786bcb |
|
| /// File Name: |
nunenews-rfi.txt |
Description:
|
NUNE News Script suffers from a remote file inclusion vulnerability in custom_admin_path.
| | Author: | xoron | | File Size: | 944 | | Last Modified: | Jan 13 16:31:24 2007 |
| MD5 Checksum: | 3b71db660f43b0ec945dd7057ba5368d |
|
| /// File Name: |
uguestbook-mdb.txt |
Description:
|
Uguestbook version 1.0 suffers from a remote password disclosure flaw.
| | Author: | beks | | File Size: | 260 | | Last Modified: | Jan 13 16:30:36 2007 |
| MD5 Checksum: | bdb2b09f5618accb2044930cf69cac46 |
|
| /// File Name: |
stego-crack.txt |
Description:
|
Steganography version 1.7.1 and 1.8 suffer from a vulnerability that allows access to encrypted files.
| | Author: | NtWaK0, NoPh0BiA | | File Size: | 3011 | | Last Modified: | Jan 13 16:30:00 2007 |
| MD5 Checksum: | a145599fa19c14ceadb35ab1bac9b06d |
|
| /// File Name: |
webulas-mdb.txt |
Description:
|
Webulas suffers from a remote password disclosure flaw.
| | Author: | beks | | File Size: | 195 | | Last Modified: | Jan 13 16:28:19 2007 |
| MD5 Checksum: | 36a228b44a04339700966d3620031c63 |
|
| /// File Name: |
harika20-mdb.txt |
Description:
|
HarikaOnline version 2.0 suffers from a remote password disclosure flaw.
| | Author: | beks | | File Size: | 237 | | Last Modified: | Jan 13 16:27:51 2007 |
| MD5 Checksum: | e3fb4f4b3b50335de2e99ba6ceca8519 |
|
| /// File Name: |
mcore-mdb.txt |
Description:
|
M-Core suffers from a remote password disclosure flaw.
| | Author: | beks | | File Size: | 196 | | Last Modified: | Jan 13 16:27:21 2007 |
| MD5 Checksum: | 33d2d6b01c99b0722c56628cff55c3e5 |
|
| /// File Name: |
mitisoft-mdb.txt |
Description:
|
MitiSoft suffers from a remote password disclosure flaw.
| | Author: | beks | | File Size: | 211 | | Last Modified: | Jan 13 16:26:57 2007 |
| MD5 Checksum: | 52cf5d3c9f2c82220e30e28adcaacf28 |
|
| /// File Name: |
ememberspro10-mdb.txt |
Description:
|
EMembersPro version 1.0 suffers from a remote password disclosure flaw.
| | Author: | beks | | File Size: | 230 | | Last Modified: | Jan 13 16:26:25 2007 |
| MD5 Checksum: | a8e4719cb787987a489217cfd91d3dba |
|
| /// File Name: |
ajlogin35-mdb.txt |
Description:
|
AJLogin versions 3.5 suffers from a remote password disclosure flaw.
| | Author: | beks | | File Size: | 234 | | Last Modified: | Jan 13 16:25:45 2007 |
| MD5 Checksum: | a31e878c5d21b97840da9e08777d95c1 |
|
| /// File Name: |
guest402.txt |
Description:
|
@lex Guestbook versions 4.0.2 and below remote command execution exploit.
| | Author: | DarkFig | | File Size: | 5093 | | Last Modified: | Jan 13 16:24:27 2007 |
| MD5 Checksum: | 0ded326b5020bc4ce0354d4e29b3ea20 |
|
| /// File Name: |
createauction-sql.txt |
Description:
|
createauction suffers from a remote SQL injection vulnerability in catid.
| | Author: | IbnuSina | | File Size: | 738 | | Last Modified: | Jan 13 16:23:33 2007 |
| MD5 Checksum: | 8a27c1648b5e4022e41c793cf2bdfc30 |
|
| /// File Name: |
shopstorenow-sql.txt |
Description:
|
The shopstorenow E-commerce Shopping Cart is vulnerable to SQL injection attacks.
| | Author: | IbnuSina | | File Size: | 655 | | Last Modified: | Jan 13 16:11:24 2007 |
| MD5 Checksum: | 63865822f42d9c4ddfc1001d8da5c9a6 |
|
| /// File Name: |
yald10-xss.txt |
Description:
|
Yet Another Link Directory version 1.0 suffers from cross site scripting flaws.
| | Author: | Luny | | File Size: | 402 | | Last Modified: | Jan 13 16:09:28 2007 |
| MD5 Checksum: | b4274bc3ba1351a5c627ce6edf9e2784 |
|
|
|
|
|