Section: .. / 0806-exploits /
| /// File Name: |
msword-crash.tgz |
Description:
|
A vulnerability has been reported in Microsoft Word, which can be exploited by malicious people to compromise the system. The vulnerability is caused due to an unspecified error when parsing malformed functions. This can be exploited to corrupt memory via a specially crafted function in a Word document. Successful exploitation allows execution of arbitrary code. Demonstration .DOC files included.
| | Author: | Ivan Sanchez | | Homepage: | http://www.nullcode.com.ar/ | | File Size: | 8489 | | Last Modified: | Jun 18 17:23:51 2008 |
| MD5 Checksum: | 26f745900a11281b808b2b886adb77bc |
|
| /// File Name: |
maxtrade-sql.txt |
Description:
|
Maxtrade AIO version 1.3.23 suffers from a remote SQL injection vulnerability in modules.php.
| | Author: | HaCkeR_EgY | | Homepage: | http://www.PaL-HaCker.com/ | | File Size: | 1139 | | Last Modified: | Jun 18 17:11:22 2008 |
| MD5 Checksum: | 14ba659cbdb0063e42ef24f75049151a |
|
| /// File Name: |
mybizz-sql.txt |
Description:
|
Mybizz-Classifieds suffers from a SQL injection vulnerability in index.php.
| | Author: | HaCkeR_EgY | | Homepage: | http://www.PaL-HaCker.com/ | | File Size: | 997 | | Last Modified: | Jun 18 17:09:52 2008 |
| MD5 Checksum: | 5dc6711263e1c6c466fc93815418ab1e |
|
| /// File Name: |
phpsitelock-sql.txt |
Description:
|
PHP Site Lock version 2.0 suffers from a remote SQL injection vulnerability in index.php.
| | Author: | Mr.SQL | | Homepage: | http://www.pal-hacker.com/ | | File Size: | 1846 | | Last Modified: | Jun 17 15:02:47 2008 |
| MD5 Checksum: | 9e62ed15d6ad1e83d0904119c83fe1db |
|
| /// File Name: |
myshoutpro-cookie.txt |
Description:
|
MyShoutPro version 1.2 Final suffers from an insecure cookie handling vulnerability.
| | Author: | Stack | | Homepage: | http://v4-team.com/ | | File Size: | 525 | | Last Modified: | Jun 17 15:02:10 2008 |
| MD5 Checksum: | 526f3fd854c83304e0f6650443dade67 |
|
| /// File Name: |
freecms-upload.txt |
Description:
|
FreeCMS version 0.2 arbitrary file upload exploit.
| | Author: | Stack | | Homepage: | http://v4-team.com/ | | File Size: | 2602 | | Last Modified: | Jun 17 15:01:23 2008 |
| MD5 Checksum: | ae07d81873d6242d094474b8e45fe287 |
|
| /// File Name: |
thaiquickcart-lfi.txt |
Description:
|
ThaiQuickCart suffers from local file inclusion vulnerabilities.
| | Author: | CWH Underground | | Homepage: | http://www.citecclub.org/ | | File Size: | 2111 | | Last Modified: | Jun 17 14:18:25 2008 |
| MD5 Checksum: | 321a7c783f3db62bfbe2cdd016620ead |
|
| /// File Name: |
easytrade-sql.txt |
Description:
|
easyTrade version 2.x suffers from a SQL injection vulnerability in detail.php.
| | Author: | h0yt3r | | File Size: | 864 | | Last Modified: | Jun 17 14:17:42 2008 |
| MD5 Checksum: | 3fb2f320237c10079f9f7cc23c33d947 |
|
| /// File Name: |
bizoncms-sql.txt |
Description:
|
Bizon-CMS version 2.0 suffers from a remote SQL injection vulnerability in index.php.
| | Author: | Mr.SQL | | Homepage: | http://www.pal-hacker.com/ | | File Size: | 1700 | | Last Modified: | Jun 17 14:17:25 2008 |
| MD5 Checksum: | 721dd0486d12e120bf774a359a416c8f |
|
| /// File Name: |
freecms-sql.txt |
Description:
|
FreeCMS version 0.2 suffers from a remote SQL injection vulnerability in index.php.
| | Author: | Mr.SQL | | Homepage: | http://www.pal-hacker.com/ | | File Size: | 1576 | | Last Modified: | Jun 17 14:15:40 2008 |
| MD5 Checksum: | 1bccfa998b3029d9292975d34f1997ca |
|
| /// File Name: |
basiccms-sql.txt |
Description:
|
BaSiC-CMS suffers from a remote SQL injection vulnerability in index.php.
| | Author: | Mr.SQL | | Homepage: | http://www.pal-hacker.com/ | | File Size: | 1671 | | Last Modified: | Jun 17 14:14:55 2008 |
| MD5 Checksum: | 53cca35e592d2da7e7b261bbf3b96750 |
|
| /// File Name: |
cep-blindsql.txt |
Description:
|
Comparison Engine Power version 1.0 blind SQL injection exploit that makes use of product.detail.php.
| | Author: | Mr.SQL | | Homepage: | http://www.pal-hacker.com/ | | File Size: | 3610 | | Last Modified: | Jun 17 14:13:16 2008 |
| MD5 Checksum: | 90a3f9953f779560bc52333681eede20 |
|
| /// File Name: |
s21sec-044-en.txt |
Description:
|
OpenDocMan version 1.2.5 suffers from a cross site scripting vulnerability.
| | Author: | Sergi Rosello | | Homepage: | http://www.s21sec.com/ | | File Size: | 1587 | | Last Modified: | Jun 17 14:12:03 2008 |
| MD5 Checksum: | 562eb1809c0cf5a98f163965ec3ef61f |
|
| /// File Name: |
clipshare301-sql.txt |
Description:
|
ClipShare versions below 3.0.1 suffer from a remote SQL injection vulnerability in group_posts.php.
| | Author: | SuNHouSe2 | | File Size: | 1409 | | Last Modified: | Jun 17 14:06:30 2008 |
| MD5 Checksum: | 72aec6170ed36e14a1f76235548d0d1c |
|
| /// File Name: |
dne2000-call.c |
Description:
|
Deterministic Network Enhancer local kernel ring0 SYSTEM exploit that makes use of dne2000.sys.
| | Author: | mu-b | | Homepage: | http://www.digit-labs.org/ | | File Size: | 6098 | | Last Modified: | Jun 17 14:04:32 2008 |
| MD5 Checksum: | d52639d7e094868d55ea53558dc96229 |
|
| /// File Name: |
skulltagloop.zip |
Description:
|
Proof of concept denial of service exploit for Skulltag versions 0.97d2-RC2 and below which suffer from a looping vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related File: | skulltagloop.txt | | File Size: | 12867 | | Last Modified: | Jun 16 20:20:21 2008 |
| MD5 Checksum: | 6c599d1d7fb08d9ced5a07d91650933c |
|
| /// File Name: |
dontcrysis-adv.txt |
Description:
|
Crysis versions 1.21 and below suffer from a NULL pointer vulnerability in the HTTP/XML-RPC service.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | File Size: | 6148 | | Last Modified: | Jun 16 20:17:51 2008 |
| MD5 Checksum: | d03677b77dbed4d5da27061d4fcd5809 |
|
| /// File Name: |
vistareseller-xss.txt |
Description:
|
VistaReseller Panel BETA suffers from a cross site scripting vulnerability.
| | Author: | IRCRASH | | Homepage: | http://ircrash.com/ | | File Size: | 949 | | Last Modified: | Jun 16 20:03:05 2008 |
| MD5 Checksum: | 9cfa7936ab3a88794eac9a4f86c963ef |
|
| /// File Name: |
DSECRG-08-026.txt |
Description:
|
Open Azimyt CMS version 0.22 minimal and 0.21 stable suffer from a local file inclusion vulnerability.
| | Author: | Digital Security Research Group | | Homepage: | http://www.dsec.ru/ | | File Size: | 3307 | | Last Modified: | Jun 16 20:02:26 2008 |
| MD5 Checksum: | 8aa2d61ac4a1bb1fb1674b4c093bb13e |
|
| /// File Name: |
smf114-sql.txt |
Description:
|
Simple Machines Forum versions 1.1.4 and below remote SQL injection exploit.
| | Author: | The:Paradox | | Homepage: | http://www.inj3ct-it.org/ | | File Size: | 10437 | | Last Modified: | Jun 16 19:58:40 2008 |
| MD5 Checksum: | cac5b41d962610887063c05f4545c5d8 |
|
| /// File Name: |
shnews-cookie.txt |
Description:
|
SH-News version 3.0 suffers from an insecure cookie handling vulnerability.
| | Author: | hadihadi | | Homepage: | http://www.virangar.org/ | | File Size: | 1057 | | Last Modified: | Jun 16 19:57:43 2008 |
| MD5 Checksum: | 7412a0e548e7f7c0be751e845387958d |
|
| /// File Name: |
mymarket-blindsql.txt |
Description:
|
MyMarket version 1.72 blind SQL injection exploit.
| | Author: | h0yt3r | | File Size: | 3697 | | Last Modified: | Jun 16 19:56:23 2008 |
| MD5 Checksum: | a5e83f736eaaee9492470d8a2b9a205c |
|
| /// File Name: |
oxygen-sql.txt |
Description:
|
Oxygen version 2.0 suffers from a remote SQL injection vulnerability.
| | Author: | h0yt3r | | File Size: | 993 | | Last Modified: | Jun 16 19:55:08 2008 |
| MD5 Checksum: | 82664d93fa862609a89b7b6eefbe12f4 |
|
|
|
|
|