Section: .. / 0709-exploits /
| /// File Name: |
coppermine1412-xss.txt |
Description:
|
Coppermine versions 1.4.12 and below suffer from cross site scripting and local file inclusion vulnerabilities.
| | Author: | L4teral | | File Size: | 1300 | | Last Modified: | Sep 18 13:02:49 2007 |
| MD5 Checksum: | 9faac6d221e52301e50736a96311fd39 |
|
| /// File Name: |
CORE-2007-0817.txt |
Description:
|
Core Security Technologies Advisory - Remote command execution, HTML and JavaScript injection vulnerabilities in AOL's Instant Messaging software. Versions 6.1, 6.2, Pro, and Lite are affected.
| | Homepage: | http://www.coresecurity.com/corelabs/ | | File Size: | 31509 | | Related CVE(s): | CVE-2007-4901 | | Last Modified: | Sep 25 22:07:53 2007 |
| MD5 Checksum: | 9f6886148c8923f1548101c7a3d286c4 |
|
| /// File Name: |
dfdcart-rfi.txt |
Description:
|
DFD Cart version 1.1 suffers from multiple remote file inclusion vulnerabilities.
| | Author: | BiNgZa | | File Size: | 1920 | | Last Modified: | Sep 24 22:36:49 2007 |
| MD5 Checksum: | cd64c492d8788c70f511532881e4c62e |
|
| /// File Name: |
ebdesign-remote.txt |
Description:
|
EB Design Pty Ltd suffers from multiple remote vulnerabilities in EBCRYPT.DLL version 2.0.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 1885 | | Last Modified: | Sep 24 22:48:33 2007 |
| MD5 Checksum: | 76b07db4dd417027b9ec32cc7983dbf5 |
|
| /// File Name: |
edraw-activex.txt |
Description:
|
EDraw Office Views component version 5.2 ActiveX remote buffer overflow proof of concept exploit.
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 2200 | | Last Modified: | Sep 7 19:10:32 2007 |
| MD5 Checksum: | 72f9c3f67ba960ed015aac0139785229 |
|
| /// File Name: |
enetman-rfi.txt |
Description:
|
eNetman version 20050830 suffers from a remote file inclusion vulnerability in index.php.
| | Author: | JaheeM | | File Size: | 246 | | Last Modified: | Sep 4 23:34:24 2007 |
| MD5 Checksum: | 9c4fffa1acb5155d077411507c1bed5f |
|
| /// File Name: |
fa113-rfi.tt |
Description:
|
FrontAccounting version 1.13 suffers from remote file inclusion vulnerabilities.
| | Author: | kezzap66345 | | File Size: | 3756 | | Last Modified: | Sep 26 22:40:58 2007 |
| MD5 Checksum: | 7cd2f345bb9716d267fcb943d81cfb6c |
|
| /// File Name: |
flip30-pass.txt |
Description:
|
Flip versions 3.0 and below remote password hash disclosure exploit.
| | Author: | undefined1_ | | Homepage: | http://www.undefl.com/ | | File Size: | 2719 | | Last Modified: | Sep 20 04:27:11 2007 |
| MD5 Checksum: | 70661dab3d3fc5f17b36e8dd18e9dec1 |
|
| /// File Name: |
gelato-sql.txt |
Description:
|
Gelato CMS remote SQL injection exploit.
| | Author: | s0cratex | | File Size: | 1500 | | Last Modified: | Sep 18 12:32:06 2007 |
| MD5 Checksum: | ab1f2f15baf21100bdc3199c1c10545d |
|
| /// File Name: |
globallink-overflow.txt |
Description:
|
GlobalLink version 2.7.0.8 dlltemCom.dll SetInfo() heap overflow exploit.
| | Author: | void | | Homepage: | http://www.ph4nt0m.org/ | | File Size: | 1584 | | Last Modified: | Sep 5 20:49:30 2007 |
| MD5 Checksum: | 8df134a1851777b7bb23f8129cbb9f3d |
|
| /// File Name: |
gmailsteal_local.scpt.txt |
Description:
|
This script can be used to steal G-Mail's keychained password by injecting javascript into Safari. When executed it opens G-Mail's login page, reads the saved password and prompts it into an alert box.
| | Author: | poplix | | Homepage: | http://px.dynalias.org/ | | File Size: | 676 | | Last Modified: | Sep 30 02:24:52 2007 |
| MD5 Checksum: | be54b1b330d258fc5c3ba6851cf17ef2 |
|
| /// File Name: |
gmailsteal_remote.scpt.txt |
Description:
|
This script can be used to steal G-Mail's keychained password by injecting javascript into Safari. When executed it opens G-Mail's login page, reads the saved password and sends it to a logging server by creating an hidden iframe into G-Mail's page.
| | Author: | poplix | | Homepage: | http://px.dynalias.org/ | | File Size: | 1165 | | Last Modified: | Sep 30 02:26:43 2007 |
| MD5 Checksum: | f25867c70c9f1546c6cf772d9272279f |
|
| /// File Name: |
gmotor2.zip |
Description:
|
Proof of concept exploit for rFactor versions 1.250 and below that suffer from buffer overflow and code execution vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | rfactox.txt | | File Size: | 12010 | | Last Modified: | Sep 20 04:57:38 2007 |
| MD5 Checksum: | 2c04ffd658ffb146eb12c1a46c568bfb |
|
| /// File Name: |
greek-rfi.txt |
Description:
|
It appears that the Greek Web Election System suffers from remote file inclusion vulnerabilities.
| | Author: | George Papandreou | | File Size: | 598 | | Last Modified: | Sep 24 23:52:31 2007 |
| MD5 Checksum: | 34af9aeedc5cd785581f77f6b60085d0 |
|
| /// File Name: |
greensql-xss.txt |
Description:
|
GreenSQL is susceptible to a permanent cross site scripting vulnerability.
| | Author: | laurent gaffi | | File Size: | 1487 | | Last Modified: | Sep 24 23:15:47 2007 |
| MD5 Checksum: | 1aff950d54a61369e175e37630de9d2c |
|
| /// File Name: |
hackersafe-plesk.txt |
Description:
|
Plesk for Windows versions 7.6.1, 8.1.0, 8.1.1, and 8.2.0 suffer from a SQL injection vulnerability.
| | Author: | Nick Merritt | | Homepage: | http://www.hackersafe.com/ | | File Size: | 2016 | | Last Modified: | Sep 12 20:00:12 2007 |
| MD5 Checksum: | f422dc43a2d2337d90b9e8966bdf2cba |
|
| /// File Name: |
hackflatnuke.txt |
Description:
|
FlatNuke version 2.6 suffers from account modification and privilege escalation vulnerabilities. Exploitation details provided.
| | Author: | darkbunny91 | | File Size: | 2272 | | Last Modified: | Sep 25 00:07:54 2007 |
| MD5 Checksum: | 6f44b7706685de22e2c7d724d0dfb3b2 |
|
| /// File Name: |
helplink010-rfi.txt |
Description:
|
Helplink version 0.1.0 suffers from a remote file inclusion vulnerability in show.php.
| | Author: | GolD_M | | Homepage: | http://www.tryag.cc/ | | File Size: | 1427 | | Last Modified: | Sep 24 22:25:38 2007 |
| MD5 Checksum: | 9cf9a17f3f665040fbe0b3f23d9b025c |
|
| /// File Name: |
hoagie_lighttpd.c |
Description:
|
Lighttpd version 1.4.17 and below FastCGI header overflow remote exploit.
| | Author: | Andi | | Homepage: | http://www.void.at/ | | File Size: | 16788 | | Last Modified: | Sep 20 20:47:57 2007 |
| MD5 Checksum: | aad99bd0395b4c024cf58996d587892c |
|
| /// File Name: |
husrev-sql.txt |
Description:
|
Husrev Forums version 2.0.1:PoWerBoard suffers from a SQL injection vulnerability.
| | Author: | Yollubunlar | | Homepage: | http://yollubunlar.org/ | | File Size: | 655 | | Last Modified: | Sep 10 15:04:20 2007 |
| MD5 Checksum: | 3eb81738b81ec016fda1397073191177 |
|
| /// File Name: |
ibmatom-xss.txt |
Description:
|
The Atom feed in www.ibm.com is susceptible to cross site scripting attacks.
| | Author: | HASEGAWA Yosuke | | File Size: | 2029 | | Last Modified: | Sep 11 18:59:48 2007 |
| MD5 Checksum: | 26f9b1f118e7cd065f82288a58f60b58 |
|
| /// File Name: |
integra-rfi.txt |
Description:
|
IntegraMOD Nederland version 1.4.2 suffers from a remote file inclusion vulnerability.
| | Author: | xoron | | File Size: | 380 | | Last Modified: | Sep 27 21:22:35 2007 |
| MD5 Checksum: | e02f9bfcac8a06e4198bab5489dec3de |
|
|
|
|
|