Section: .. / 1001-exploits /
| /// File Name: |
rt-sa-2010-002.txt |
Description:
|
During a penetration test, RedTeam Pentesting discovered that the GNCaster software does not handle NMEA-data correctly. An attacker that has valid login credentials can use this to crash the server software or potentially execute code on the server. Versions 1.4.0.7 and below are affected.
| | Homepage: | http://www.redteam-pentesting.de/ | | File Size: | 4170 | | Last Modified: | Jan 27 13:38:36 2010 |
| MD5 Checksum: | 3e2c933a8d60fc962fa41f41e23de87e |
|
| /// File Name: |
SA-20100115-0.txt |
Description:
|
LetoDMS versions 1.7.2 and below suffer from cross site request forgery and local file inclusion vulnerabilities.
| | Author: | Daniel Fabian,Lukas Weichselbaum | | Homepage: | http://www.sec-consult.com | | File Size: | 4486 | | Last Modified: | Jan 15 20:06:10 2010 |
| MD5 Checksum: | 4ea74d7fa9611a6a57792630447e477e |
|
| /// File Name: |
safari404-dos.txt |
Description:
|
Safari version 4.0.4 suffers from a javascript crash denial of service vulnerability.
| | Author: | systemx00 | | File Size: | 1238 | | Last Modified: | Jan 26 01:56:50 2010 |
| MD5 Checksum: | b55c4e1f730b1f5f7cc74d4711f7748f |
|
| /// File Name: |
safecentral-unharden-v2.c |
Description:
|
Authentium SafeCentral versions 2.6 and below shdrv.sys local kernel ring0 SYSTEM proof of concept exploit. Version 2 of this exploit.
| | Author: | mu-b | | Homepage: | http://www.digit-labs.org/ | | File Size: | 9915 | | Last Modified: | Jan 17 18:34:18 2010 |
| MD5 Checksum: | 4bc1701a8953e59e7a82269586643986 |
|
| /// File Name: |
safecentral-unharden.c |
Description:
|
Authentium SafeCentral versions 2.6 and below shdrv.sys local kernel ring0 SYSTEM proof of concept exploit.
| | Author: | mu-b | | Homepage: | http://www.digit-labs.org/ | | File Size: | 2367 | | Last Modified: | Jan 17 18:32:43 2010 |
| MD5 Checksum: | 085d270c487ea8e801e432effe1a94e6 |
|
| /// File Name: |
safecms-xss.txt |
Description:
|
SafeCms versions 2.0.1.0 and below suffer from a cross site scripting vulnerability.
| | Author: | cp77fk4r | | File Size: | 396 | | Last Modified: | Jan 7 00:02:01 2010 |
| MD5 Checksum: | 041466ffc882fe39c6af72dfb9f0f7d3 |
|
| /// File Name: |
samplelord-xss.txt |
Description:
|
SAMPLE Lord version 1.0 suffers from a cross site scripting vulnerability.
| | Author: | R3d-D3v!L | | File Size: | 1604 | | Last Modified: | Jan 7 00:06:54 2010 |
| MD5 Checksum: | 1c0b9bcd5da47caf0ddd7b3a2f0b1cd8 |
|
| /// File Name: |
sbddirectory-xss.txt |
Description:
|
SBD Directory version 4.0 suffers from a cross site scripting vulnerability.
| | Author: | Crux | | File Size: | 1345 | | Last Modified: | Jan 12 17:25:18 2010 |
| MD5 Checksum: | 03accaa66a9b866dcc98d634e3259224 |
|
| /// File Name: |
seriallib-xss.txt |
Description:
|
The Arabic version of Serial Lib suffers from a cross site scripting vulnerability.
| | Author: | indoushka | | File Size: | 3231 | | Last Modified: | Jan 3 21:15:38 2010 |
| MD5 Checksum: | 1b58378fcd1f8bb3cae690c4154e9789 |
|
| /// File Name: |
serialsws-xss.txt |
Description:
|
Serials.ws version 1.0.4 PHP Clone Script suffers from a cross site scripting vulnerability.
| | Author: | indoushka | | File Size: | 1428 | | Last Modified: | Jan 18 20:50:14 2010 |
| MD5 Checksum: | 89bae53bb73edafcd2733fad624b70d2 |
|
| /// File Name: |
servicedupload-shell.txt |
Description:
|
Service D'Upload version 1.0.0 suffers from a remote shell upload vulnerability.
| | Author: | indoushka | | File Size: | 3074 | | Last Modified: | Jan 3 22:28:39 2010 |
| MD5 Checksum: | 8e6b7fa14ab422774b07437d79a341b6 |
|
| /// File Name: |
sharetronix-xss.txt |
Description:
|
ShareTronix version 1.0.4 suffers from a html injection / cross site scripting vulnerability.
| | Author: | MaXe | | File Size: | 1281 | | Last Modified: | Jan 27 11:21:29 2010 |
| MD5 Checksum: | f7ad9f2ebbce1f0b8a3efb950ab36fee |
|
| /// File Name: |
silverstripe-xsrf.txt |
Description:
|
Silverstripe versions 2.0.0 and below suffer from cross site request forgery and open redirection vulnerabilities.
| | Author: | cp77fk4r | | File Size: | 2802 | | Last Modified: | Jan 24 15:28:16 2010 |
| MD5 Checksum: | 9f60cf825e07bf80ed42e2e7582fd628 |
|
| /// File Name: |
silverstripecms-xss.txt |
Description:
|
Silverstripe CMS versions 2.3.4 and below suffer from cross site scripting vulnerabilities.
| | Author: | Moritz Naumann | | File Size: | 1569 | | Last Modified: | Jan 22 18:37:30 2010 |
| MD5 Checksum: | 144b6d35f058f5f646eda67d146946b0 |
|
| /// File Name: |
simplephpblog511-xss.txt |
Description:
|
Simple PHP Blog version 5.11 suffers from a cross site scripting vulnerability.
| | Author: | Sora | | File Size: | 558 | | Last Modified: | Jan 12 21:39:44 2010 |
| MD5 Checksum: | c284112c2fa4da958e43cd2f501efbaa |
|
| /// File Name: |
simplephpgb-xss.txt |
Description:
|
Simple PHP Guestbook suffers from a cross site scripting vulnerability.
| | Author: | R3d-D3v!L | | File Size: | 1756 | | Last Modified: | Jan 11 13:53:32 2010 |
| MD5 Checksum: | f281e34662a0f6f5b12c257a609e87b8 |
|
| /// File Name: |
simplyclassified-xssxsrf.txt |
Description:
|
Simply Classified version 0.2 suffers from cross site request forgery and cross site scripting vulnerabilities.
| | Author: | mr_me | | Related Exploit: | simplyclassified-sql.txt | | File Size: | 3268 | | Last Modified: | Jan 11 13:46:06 2010 |
| MD5 Checksum: | 2e5855ab5c598e43e43e27e645e75f73 |
|
| /// File Name: |
sketchup.py.txt |
Description:
|
Google SketchUp versions 7.1.6087 and below lib3ds 3DS importer memory corruption exploit.
| | Author: | mr_me | | Related File: | CORE-2009-1209.txt | | File Size: | 12898 | | Last Modified: | Jan 17 17:36:07 2010 |
| MD5 Checksum: | d4fe047fc4d39f8dd79c19ad2df8812d |
|
| /// File Name: |
skypelinux-dos.txt |
Description:
|
Skype for Linux versions 2.1 Beta and below suffer from some odd denial of service and html injection issues that can assist phishing attacks.
| | Author: | crossbower,emgent | | File Size: | 3131 | | Last Modified: | Jan 4 18:59:53 2010 |
| MD5 Checksum: | ca6b3f75f345f95951e81db5aa3a0fae |
|
| /// File Name: |
skyportal-disclose.txt |
Description:
|
ASP SkyPortal version 1 suffers from a remote database download vulnerability.
| | Author: | indoushka | | File Size: | 2949 | | Last Modified: | Jan 4 19:01:18 2010 |
| MD5 Checksum: | 8aeeb505836eebdcc53269bd613c167c |
|
| /// File Name: |
slaedcms-xssbackup.txt |
Description:
|
The Arabic version of SLAED CMS version 2.0 suffers from cross site scripting and backup related vulnerabilities.
| | Author: | indoushka | | File Size: | 3273 | | Last Modified: | Jan 3 23:16:08 2010 |
| MD5 Checksum: | bc44fadb13dc7ad462a89926cc8bd18e |
|
| /// File Name: |
slk.rar |
Description:
|
OpenOffice versions 3.1.1 and 3.1.0 .slk file parsing null pointer proof of concept exploit.
| | Author: | Hellcode Research | | File Size: | 434 | | Last Modified: | Jan 19 20:32:39 2010 |
| MD5 Checksum: | b0338b3393845756970932d64d97a358 |
|
| /// File Name: |
smartphpstat-xss.txt |
Description:
|
Smart PHP Statistics version 1.0 suffers from a cross site scripting vulnerability.
| | Author: | R3d-D3v!L | | File Size: | 1785 | | Last Modified: | Jan 11 15:26:24 2010 |
| MD5 Checksum: | a1a1c89f088e89b964424eacc8c367a6 |
|
|
|
|
|