Section: .. / 0801-exploits /
| /// File Name: |
snetworks-rfi.txt |
Description:
|
SNetworks PHP Classifieds version 5.0 suffers from a remote file inclusion vulnerability.
| | Author: | Crackers_Child | | File Size: | 1625 | | Last Modified: | Jan 5 19:18:05 2008 |
| MD5 Checksum: | 85ff16ef11d3201a3b92320890de1778 |
|
| /// File Name: |
tribisur-sql.txt |
Description:
|
Tribisur versions 2.0 and below remote SQL injection exploit.
| | Author: | x0kster | | File Size: | 3380 | | Last Modified: | Jan 5 19:16:27 2008 |
| MD5 Checksum: | df59b93e8049773067947eeeb242405f |
|
| /// File Name: |
coolplayer217-overflow.txt |
Description:
|
CoolPlayer version 2.17 .m3u playlist stack overflow exploit that binds a shell to port 4444.
| | Author: | Trancek | | Related File: | coolplayer-overflow.txt | | File Size: | 3028 | | Last Modified: | Jan 5 19:14:41 2008 |
| MD5 Checksum: | a0506f18c97386e7552ffa9405628953 |
|
| /// File Name: |
ipb217-xsssql.txt |
Description:
|
Invision Power Board version 2.1.7 suffers from cross site scripting and SQL injection vulnerabilities.
| | Author: | Eugene Minaev | | Homepage: | http://itdefence.ru/ | | File Size: | 3650 | | Last Modified: | Jan 5 19:04:50 2008 |
| MD5 Checksum: | b051ffe4f645813a3cd7b46c26fcfd97 |
|
| /// File Name: |
mysqlo.zip |
Description:
|
MySQL versions 6.0.3 and below pre-auth buffer overflow exploit that makes use of a vulnerability in yaSSL versions 1.7.5 and below.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | yasslick.txt | | File Size: | 7903 | | Last Modified: | Jan 4 20:26:12 2008 |
| MD5 Checksum: | 62f25e67c23e48895b17ef6e46434908 |
|
| /// File Name: |
yasslick.zip |
Description:
|
Proof of concept code that demonstrates invalid memory access and buffer overflow vulnerabilities in yaSSL versions 1.75 and below.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | yasslick.txt | | File Size: | 7813 | | Last Modified: | Jan 4 20:23:20 2008 |
| MD5 Checksum: | a33ae8f79e61ca61b15b6ccb143cf840 |
|
| /// File Name: |
urlevasion.txt |
Description:
|
URL filtering bypass proof of concept exploit that demonstrates Fortinet's filtering vulnerability.
| | Author: | Danux | | File Size: | 8138 | | Last Modified: | Jan 4 19:21:02 2008 |
| MD5 Checksum: | b79df8379509e8f6001d8c846497cd62 |
|
| /// File Name: |
samphpweb-rfi.txt |
Description:
|
samPHPweb suffers from a remote file inclusion vulnerability in db.php.
| | Author: | Crackers_Child | | File Size: | 1819 | | Last Modified: | Jan 4 19:15:20 2008 |
| MD5 Checksum: | 9328247849d715787861662c2c374e53 |
|
| /// File Name: |
netrisk-rfilfi.txt |
Description:
|
NetRisk versions 1.9.7 and below suffer from remote file inclusion and local file inclusion vulnerabilities.
| | Author: | S.W.A.T. | | Homepage: | http://www.xmors.com/ | | File Size: | 2036 | | Last Modified: | Jan 4 19:14:26 2008 |
| MD5 Checksum: | 46d99364cc29c3ac7e98636c88a44113 |
|
| /// File Name: |
vuln-summary.txt |
Description:
|
A digest of vulnerabilities listing specific findings for WordPress, AwesomeTemplateEngine, PRO-Search, RotaBanner Local, and ExpressionEngine.
| | Homepage: | http://websecurity.com.ua/ | | File Size: | 11787 | | Last Modified: | Jan 3 18:17:14 2008 |
| MD5 Checksum: | 9ebad34bd61e45aea07adcfe9fdbabcf |
|
| /// File Name: |
w3msql-xss.txt |
Description:
|
W3-mSQL suffers from a cross site scripting vulnerability that leverages a lack of user input sanitization during redisplay on an error page.
| | Author: | Vivek | | File Size: | 642 | | Last Modified: | Jan 3 13:37:40 2008 |
| MD5 Checksum: | 92fc7476cb5266551f626c7b35912a29 |
|
| /// File Name: |
siteatschool-sql.txt |
Description:
|
Site@School versions 2.3.10 and below remote blind SQL injection exploit that makes use of slideshow_full.php.
| | Author: | EgiX | | File Size: | 5459 | | Last Modified: | Jan 3 13:20:40 2008 |
| MD5 Checksum: | cf226e79e0df10aab83c93d9b8206a7b |
|
| /// File Name: |
myphp30-sql.txt |
Description:
|
MyPHP Forum versions 3.0 and below suffer from multiple SQL injection vulnerabilities.
| | Author: | The:Paradox | | Homepage: | http://www.inj3ct-it.org/ | | File Size: | 6894 | | Last Modified: | Jan 3 13:19:31 2008 |
| MD5 Checksum: | 639a2407db743221b057dfe6e87346ca |
|
| /// File Name: |
gswsshit.zip |
Description:
|
Proof of concept code that demonstrates format string and buffer overflow vulnerabilities in Georgia SoftWorks SSH2 Server versions 7.01.0003 and below.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | gswsshit.txt | | File Size: | 77423 | | Last Modified: | Jan 2 17:53:39 2008 |
| MD5 Checksum: | f2be8cdd38695547a1d1d65bead4ef59 |
|
| /// File Name: |
whitedunboffs.zip |
Description:
|
Proof of concept code that demonstrates buffer overflow and format string vulnerabilities in White Dune versions 0.29beta791 and below.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | whitedunboffs.txt | | File Size: | 476 | | Last Modified: | Jan 2 17:51:15 2008 |
| MD5 Checksum: | 79442978ff2035ad8161c9f0a5313b17 |
|
| /// File Name: |
phpbb2022-xss.txt |
Description:
|
phpBB version 2.0.22 suffers from a cross site scripting vulnerability in admin_groups.php.
| | Author: | Alfredo Panzera | | Homepage: | http://www.opencosmo.com/ | | File Size: | 234 | | Last Modified: | Jan 2 17:48:59 2008 |
| MD5 Checksum: | bf964c35457a818911b2416d69014025 |
|
| /// File Name: |
phpwebsite-xss.txt |
Description:
|
phpWebSite version 1.4.0 suffers from a cross site scripting vulnerability that can be leveraged via the search functionality.
| | Author: | Audun Larsen | | File Size: | 1537 | | Last Modified: | Jan 1 17:32:02 2008 |
| MD5 Checksum: | 0b102b5e3eac4f0e0033ac2d1115d2fd |
|
| /// File Name: |
clipshare-sql.txt |
Description:
|
clipshare suffers from a remote SQL injection vulnerability in uprofile.php.
| | Author: | Krit | | Homepage: | http://www.thaishadow.com/ | | File Size: | 1025 | | Last Modified: | Jan 1 17:30:22 2008 |
| MD5 Checksum: | 02598bf2edd92441c8ead56d8e7c0c55 |
|
| /// File Name: |
agency-disclose.txt |
Description:
|
AGENCY4NET WEBFTP version 1 suffers from a file disclosure vulnerability in download2.php.
| | Author: | GolD_M | | Homepage: | http://www.tryag.cc/ | | File Size: | 1362 | | Last Modified: | Jan 1 17:28:24 2008 |
| MD5 Checksum: | 93ae36bba87a0113edb5074e1ebe07e9 |
|
| /// File Name: |
joomlapuarcade-sql.txt |
Description:
|
The Joomla component PU Arcade Remote versions 2.1.3 and below suffer from a SQL injection vulnerability.
| | Author: | H-T Team | | Homepage: | http://no-hack.fr/ | | File Size: | 1072 | | Last Modified: | Jan 1 17:26:53 2008 |
| MD5 Checksum: | d8a856c04849078398115e91de080cfe |
|
| /// File Name: |
webportalcms-sql.txt |
Description:
|
WebPortal CMS versions 0.6.0 and below remote SQL injection exploit that makes use of index.php.
| | Author: | x0kster | | File Size: | 1642 | | Last Modified: | Jan 1 17:24:43 2008 |
| MD5 Checksum: | 6573085f890b5a3cd4e15792953f1f74 |
|
|
|
|
|