<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Last 50</title>
	<link>http://packetstormsecurity.org/</link>
	<description>50 Most Recent Packet Storm File Additions</description>
	<language>en-us</language>

<item>
	<title>uninformed-10.tgz</title>
	<link>http://packetstormsecurity.org/groups/uninformed/uninformed-10.tgz</link>
	<description>Uninformed is pleased to announce the release of its tenth volume which is composed of 4 articles: Can you find me now? Unlocking the Verizon Wireless xv6800 (HTC Titan), Using dual-mappings to evade automated unpacker, Analyzing local privilege escalations in win32k, and Exploiting Tomorrow's Internet Today: Penetration testing with IPv6. </description>
</item>
<item>
	<title>dsa-1653-1.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/dsa-1653-1.txt</link>
	<description>Debian Security Advisory 1653-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. </description>
</item>
<item>
	<title>indexscript30-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/indexscript30-sql.txt</link>
	<description>IndexScript version 3.0 suffers from a remote SQL injection vulnerability in sug_cat.php. </description>
</item>
<item>
	<title>marvell-association.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/marvell-association.txt</link>
	<description>The wireless drivers in some Wi-Fi access points (such as the MARVELL-based Linksys WAP4400N) do not correctly parse some malformed 802.11 frames, allowing for denial of service and possible code execution.  </description>
</item>
<item>
	<title>globsy-rewrite.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/globsy-rewrite.txt</link>
	<description>Globsy versions 1.0 and below remote file rewriting exploit. </description>
</item>
<item>
	<title>createdirectory2sysdba.sql</title>
	<link>http://packetstormsecurity.org/0810-exploits/createdirectory2sysdba.sql</link>
	<description>Proof of concept code that demonstrates how an Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB. </description>
</item>
<item>
	<title>create_any_directory_to_sysdba.pdf</title>
	<link>http://packetstormsecurity.org/papers/database/create_any_directory_to_sysdba.pdf</link>
	<description>An Oracle DB user which has been granted CREATE ANY DIRECTORY can use that system privilege to grant themselves the SYSDBA system privilege by creating a DIRECTORY pointing to the password file location on the OS and then overwriting it with a previously prepared known binary password file using UTL_FILE.PUT_RAW from within the DB. This paper will show how the issue can be exploited and most importantly how to secure against it. </description>
</item>
<item>
	<title>lokicms034-exec.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/lokicms034-exec.txt</link>
	<description>LokiCMS versions 0.3.4 and below remote command execution exploit. </description>
</item>
<item>
	<title>lokicms-lfi.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/lokicms-lfi.txt</link>
	<description>Loki CMS version 0.3.4 create local file inclusion exploit that uses admin.php. </description>
</item>
<item>
	<title>lokicms-check.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/lokicms-check.txt</link>
	<description>Loki CMS versions 0.3.4 and below arbitrary check file exploit that uses index.php. </description>
</item>
<item>
	<title>myphpindexer-download.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/myphpindexer-download.txt</link>
	<description>My PHP Indexer version 1.0 suffers from a local file download vulnerability in index.php. </description>
</item>
<item>
	<title>res-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/res-sql.txt</link>
	<description>Real Estate Scripts 2008 suffers from a remote SQL injection vulnerability in index.php. </description>
</item>
<item>
	<title>zomplog39-xss.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/zomplog39-xss.txt</link>
	<description>Zomplog version 3.9 suffers from a cross site scripting vulnerability. </description>
</item>
<item>
	<title>web_vuln-en.txt</title>
	<link>http://packetstormsecurity.org/papers/attack/web_vuln-en.txt</link>
	<description>Web Vulnerabilities To Gain Access To The System - A paper that goes into detail on the exploitation of local/remote file inclusion and blind SQL injection vulnerabilities. </description>
</item>
<item>
	<title>phprs-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/phprs-sql.txt</link>
	<description>phpRS version 2.8.0 suffers from a remote SQL injection vulnerability in kforum.php. </description>
</item>
<item>
	<title>raiden-dos.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/raiden-dos.txt</link>
	<description>RaidenFTPD version 2.4 build 3620 remote denial of service exploit. </description>
</item>
<item>
	<title>newlife-cookiesql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/newlife-cookiesql.txt</link>
	<description>NewLife Blogger version 3.0 and below suffer from insecure cookie handling and SQL injection vulnerabilities. </description>
</item>
<item>
	<title>xmeasy560-dos.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/xmeasy560-dos.txt</link>
	<description>XM Easy Personal FTP server version 5.6.0 remote denial of service exploit. </description>
</item>
<item>
	<title>iltaweb-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/iltaweb-sql.txt</link>
	<description>Iltaweb Alisveris Sistemi suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>2008-002-lenovornr.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/2008-002-lenovornr.txt</link>
	<description>Lenovo Rescue and Recovery version 4.20 suffers from a heap overflow in the file system filter kernel driver which could allow an attacker to overwrite kernel memory leading to elevation of privilege. </description>
</item>
<item>
	<title>guildftpd-dos.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/guildftpd-dos.txt</link>
	<description>GuildFTPd versions 0.999.8.11 and 0.999.14 heap corruption proof of concept denial of service exploit. </description>
</item>
<item>
	<title>openca-base-1.0.1.tar.gz</title>
	<link>http://packetstormsecurity.org/crypt/openca-base-1.0.1.tar.gz</link>
	<description>The OpenCA Project is a collaborative effort to develop a robust, full-featured and Open Source out-of-the-box Certification Authority implementing the most used protocols with full-strength cryptography world-wide. OpenCA is based on many Open-Source Projects. Among the supported software is OpenLDAP, OpenSSL, Apache Project, Apache mod_ssl.</description>
</item>
<item>
	<title>emf_MS08-046.rar</title>
	<link>http://packetstormsecurity.org/0810-exploits/emf_MS08-046.rar</link>
	<description>Microsoft Windows EMR_SETICMPROFILEA heap overflow denial of service exploit. </description>
</item>
<item>
	<title>minipub03-multi.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/minipub03-multi.txt</link>
	<description>mini-pub versions 0.3 and below suffer from local directory traversal and file disclosure vulnerabilities. </description>
</item>
<item>
	<title>apm-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/apm-sql.txt</link>
	<description>Absolute Poll Manager XE version 4.1 suffers from a remote SQL injection vulnerability in xlacomments.asp. </description>
</item>
<item>
	<title>cubecartcms-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/cubecartcms-sql.txt</link>
	<description>This is an old SQL injection vulnerability for CubeCart CMS that has further details on exploitation since the original report surfaced years back. </description>
</item>
<item>
	<title>dsa-1652-1.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/dsa-1652-1.txt</link>
	<description>Debian Security Advisory 1652-1 - Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service and other security problems. </description>
</item>
<item>
	<title>dsa-1651-1.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/dsa-1651-1.txt</link>
	<description>Debian Security Advisory 1651-1 - Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service and other security problems. </description>
</item>
<item>
	<title>dsa-1650-1.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/dsa-1650-1.txt</link>
	<description>Debian Security Advisory 1650-1 - Cameron Hotchkies discovered that the OpenLDAP server slapd, a free implementation of the Lightweight Directory Access Protocol, could be crashed by sending malformed ASN1 requests. </description>
</item>
<item>
	<title>MDVSA-2008-210-1.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/MDVSA-2008-210-1.txt</link>
	<description>Mandriva Linux Security Advisory - CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string. The updated packages have been patched to fix the issue. This update was too late for inclusion in Mandriva Linux 2009, so it is being released now for that version. </description>
</item>
<item>
	<title>MDVSA-2008-211.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/MDVSA-2008-211.txt</link>
	<description>Mandriva Linux Security Advisory - A buffer overflow in the SGI image format decoding routines used by the CUPS image converting filter imagetops was discovered. An attacker could create malicious SGI image files that could possibly execute arbitrary code if the file was printed. An integer overflow flaw leading to a heap buffer overflow was found in the Text-to-PostScript texttops filter. An attacker could create a malicious text file that could possibly execute arbitrary code if the file was printed. Finally, an insufficient buffer bounds checking flaw was found in the HP-GL/2-to-PostScript hpgltops filter. An attacker could create a malicious HP-GL/2 file that could possibly execute arbitrary code if the file was printed. The updated packages have been patched to prevent this issue; for Mandriva Linux 2009.0 the latest CUPS version (1.3.9) is provided that corrects these issues and also provides other bug fixes. </description>
</item>
<item>
	<title>dsa-1646-2.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/dsa-1646-2.txt</link>
	<description>Debian Security Advisory 1646-2 - In DSA 1646-1, an update was announced for a denial of service vulnerability in squid, a caching proxy server. Due to an error in packaging and in testing, the updated packages did not correct the weakness. An updated release is available which corrects the error. A weakness has been discovered in squid, a caching proxy server. The flaw was introduced upstream in response to CVE-2007-6239, and announced by Debian in DSA-1482-1. The flaw involves an over-aggressive bounds check on an array resize, and could be exploited by an authorized client to induce a denial of service condition against squid. </description>
</item>
<item>
	<title>cabrightstor-exec.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/cabrightstor-exec.txt</link>
	<description>CA BrightStor ARCServe BackUp is an overall data backup solution. The RPC interface of CA BrightStor ARCServe BackUp does not handle user's input exactly that allows anonymous attacker to inject any command, a remote code execution attack may achieved through this way. Details are provided. CA BrightStor ARCServe BackUp version R11.5 is affected. </description>
</item>
<item>
	<title>joomlajeux-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/joomlajeux-sql.txt</link>
	<description>The Joomla Jeux component version 1.0.0 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlavideos-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/joomlavideos-sql.txt</link>
	<description>The Joomla Videos component version 1.0.0 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlaphotos-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/joomlaphotos-sql.txt</link>
	<description>The Joomla Photos component version 1.0.0 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlaflash-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/joomlaflash-sql.txt</link>
	<description>The Joomla Flash component version 1.0.0 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlaownbiblio-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/joomlaownbiblio-sql.txt</link>
	<description>The Joomla ownbiblio component version 1.5.3 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>eebcms-xss.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/eebcms-xss.txt</link>
	<description>EEB-CMS version 0.95 suffers from a cross site scripting vulnerability. </description>
</item>
<item>
	<title>slimcms-escalate.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/slimcms-escalate.txt</link>
	<description>SlimCMS versions 1.0.0 and below privilege escalation exploit that uses redirect.php. </description>
</item>
<item>
	<title>ZDI-08-067.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/ZDI-08-067.txt</link>
	<description>A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple CUPS. Authentication is not required to exploit this vulnerability. The specific flaw exists in the Hewlett-Packard Graphics Language filter. Inadequate bounds checking on the pen width and pen color opcodes result in an arbitrary memory overwrite allowing for the execution of arbitrary code as the  hgltops  process uid. </description>
</item>
<item>
	<title>CVE-2008-3271.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/CVE-2008-3271.txt</link>
	<description>Apache Tomcat versions 4.1.0 to 4.1.31 and 5.5.0 suffer from an information disclosure vulnerability. </description>
</item>
<item>
	<title>joomlamad4-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/joomlamad4-sql.txt</link>
	<description>The Joomla mad4joomla component suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlaignite-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/joomlaignite-sql.txt</link>
	<description>The Joomla Ignite Gallery component version 0.8.3 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>easynet4ulink-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/easynet4ulink-sql.txt</link>
	<description>Easynet4u Link Host suffers from a remote SQL injection vulnerability in directory.php. </description>
</item>
<item>
	<title>easynet4uforum-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/easynet4uforum-sql.txt</link>
	<description>Easyney4u Forum Host suffers from a remote SQL injection vulnerability in forum.php. </description>
</item>
<item>
	<title>easynet4ufaq-sql.txt</title>
	<link>http://packetstormsecurity.org/0810-exploits/easynet4ufaq-sql.txt</link>
	<description>Easyney4u FAQ Host suffers from a remote SQL injection vulnerability in faq.php. </description>
</item>
<item>
	<title>USN-651-1.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/USN-651-1.txt</link>
	<description>Ubuntu Security Notice 651-1 - A large amount of vulnerabilities have been addressed in Ruby. These issues include integer overflow, bypass, input validation, and various other vulnerabilities. </description>
</item>
<item>
	<title>nokiaminimap-crash.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/nokiaminimap-crash.txt</link>
	<description>The Nokia Mini Map Browser suffers from a silent crash vulnerability. </description>
</item>
<item>
	<title>FSC20081009-11.txt</title>
	<link>http://packetstormsecurity.org/0810-advisories/FSC20081009-11.txt</link>
	<description>A vulnerability has been discovered in the Tape Engine component of CA ARCserve Backup. Insufficient input validation when processing remote procedure call (RPC) requests is the cause of this vulnerability. </description>
</item></channel>
</rss>
