exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 29 RSS Feed

Files Date: 2010-06-17

Microsoft Visual Studio Msmask32.ocx ActiveX Buffer Overflow.
Posted Jun 17, 2010
Authored by koshi, MC | Site metasploit.com

This Metasploit module exploits a stack buffer overflow in Microsoft's Visual Studio 6.0. When passing a specially crafted string to the Mask parameter of the Msmask32.ocx ActiveX Control, an attacker may be able to execute arbitrary code.

tags | exploit, overflow, arbitrary, activex
advisories | CVE-2008-3704
SHA-256 | def095f5fae66e555774c80c31922aee92bbe086dec4cbf1548a0683a892e8c5
PenPals 1.0 SQL Injection
Posted Jun 17, 2010
Authored by L0rd CrusAd3r

PenPals version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

tags | exploit, remote, sql injection
SHA-256 | ed95f8b8be7752b1c32578b0733c88f3daf58b9186f0d98cb97200da517c7118
MIMEDefang Email Scanner 2.69
Posted Jun 17, 2010
Authored by Dianne Skoll | Site mimedefang.org

MIMEDefang is a flexible MIME email scanner designed to protect Windows clients from viruses. Includes the ability to do many other kinds of mail processing, such as replacing parts of messages with URLs. It can alter or delete various parts of a MIME message according to a very flexible configuration file. It can also bounce messages with unacceptable attachments. MIMEDefang works with the Sendmail 8.11 and newer "Milter" API, which makes it more flexible and efficient than procmail-based approaches.

Changes: This release contains mostly minor cleanups and bugfixes. However, a new "-y" option for mimedefang-multiplexor allows you to limit the number of concurrent "recipok" commands on a per-domain basis. This can avoid a DoS situation if one domain has a slow or down SMTP call-ahead server.
systems | windows, unix
SHA-256 | 748b9c33dcb3214fab6c7798e140405187a3fb4b71e9b5e184fd4b5e46428e90
AgentSmith Log Monitor 0.1
Posted Jun 17, 2010
Authored by Rafael Ostertag | Site guengel.ch

agentsmith is a daemon that continuously monitors a log file for break-in attempts by remote hosts. Upon detection of a break-in attempt, it launches a user defined script or application, which can do virtually anything from sending mail messages to whatever else you might think of. The criteria for what is considered a break-in attempt can be configured by means of a regular expression.

tags | remote
systems | unix
SHA-256 | 2fd6257852996ba88a353a3c39ff46e2177ff75fa360a82dd7caeca82c528dc5
iCommander Command And Control 0.3
Posted Jun 17, 2010
Site icommander.isecur1ty.org

iCommander is a free and open source Command and Control Centre that lets you manage multiple servers from one place. The idea of iCommander is to provide an easy and secure solution for system administrators that allows them to control several servers from one place and in the same time.

Changes: Protocol commands data compression added. The installer and iCommander\'s updater have improved. Various other changes and fixes.
systems | unix
SHA-256 | 73f3055a6a1ca8b5e80b3a19e36b165a9642add50ff7c81b5f9d42581cd2fc7e
Easy Travel Portal SQL Injection
Posted Jun 17, 2010
Authored by L0rd CrusAd3r

Easy Travel Portal suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 887cb6cabe73f309c70c0c7cb2f12c7e92cf905430b81866a605cf744c9b8a99
iDEFENSE Security Advisory 2010-06-16.1
Posted Jun 17, 2010
Authored by iDefense Labs, Jun Mao | Site idefense.com

iDefense Security Advisory 06.16.10 - Remote exploitation of a buffer overflow vulnerability within Samba Project's Samba could allow an attacker to execute arbitrary code with root privileges. This vulnerability exists in a certain function within Samba, where an attacker could trigger a memory corruption by sending specially crafted SMB requests resulting in heap memory overwritten with attacker supplied data, which can allow attackers to execute code remotely. iDefense has confirmed the existence of this vulnerability in Samba version 3.3.12. Previous versions are suspected to be affected.Samba 3.4.0 and newer versions rewrite the whole logic of the vulnerable function and thus are not affected by this vulnerability.

tags | advisory, remote, overflow, arbitrary, root
advisories | CVE-2010-2063
SHA-256 | 0f3906ee46ff98f1da265c6dd01ae1df772e0d26f20fe6ac2c61cfa40c024efd
EQdkp-Plus Gallery Shell Upload
Posted Jun 17, 2010
Authored by H-R4F

EQdkp-Plus Gallery suffers from a shell upload vulnerability.

tags | exploit, shell
SHA-256 | 1b3870ffc008156ce9ed5b10c4a449ced61f40f4c8cc85db3fe43475201568a3
Weevely PHP Trojan
Posted Jun 17, 2010

Weevely is a PHP trojan that hides a backdoor for communication using a fake HTTP_REFERER header. Archive password is set to p4ssw0rd. Use at your own risk.

tags | trojan, php
SHA-256 | cf94575c893708f95eb4a55035795ab332e4ea43d663319a5d7ef61efd4d7224
Traidnt Discovery Cross Site Request Forgery
Posted Jun 17, 2010
Authored by G0D-F4Th3r

Traidnt Discovery suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 0641e4c162ff143e5861131b1cc97542dc20b49808b477807e082e39d1514939
SAP J2EE Telnet Administration Security Check Bypass
Posted Jun 17, 2010
Site onapsis.com

SAP J2EE Telnet Administration suffers from an authentication bypass vulnerability.

tags | advisory, bypass
SHA-256 | 1a80e20e80a3c1db1a6e588e5955e080382df05484aa9d8c7c179a6d923eec1d
Zero Day Initiative Advisory 10-110
Posted Jun 17, 2010
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 10-110 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player. User interaction is required in that a target must visit a malicious website. The specific flaw exists within the code for parsing embedded image data within SWF files. The DefineBits tag and several of its variations are prone to a parsing issue while handling JPEG data. Specifically, the vulnerability is due to decompression routines that do not validate image dimensions sufficiently before performing operations on heap memory. An attacker can exploit this vulnerability to execute arbitrary code under the context of the user running the browser.

tags | advisory, remote, arbitrary
advisories | CVE-2010-2171
SHA-256 | ac57012b1da744853d08508a20989f6d770c79f5be724971ee6fdb073b1e50f3
Zero Day Initiative Advisory 10-109
Posted Jun 17, 2010
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 10-109 - This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the code responsible for parsing embedded MP4 files. When handling the STSC, STSZ, and STCO atoms the player can be made to improperly calculate length values later used as size parameters during memory copy operations. By providing a specially crafted file an attacker can corrupt heap memory and execute arbitrary code under the context of the currently logged in user.

tags | advisory, arbitrary
advisories | CVE-2010-2162
SHA-256 | 055f900abb9dc3fbae2023801bcf07f4aa123aa4e0bf5e50b27e5c87c5db9540
Zero Day Initiative Advisory 10-108
Posted Jun 17, 2010
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 10-108 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard OpenView Network Node Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ovwebsnmpsrv.exe process which can be reached remotely through the jovgraph.exe CGI program. By supplying overly large values to variables passed through an HTTP request a strcpy call within the main() function can be made to overflow a static buffer. An attacker can leverage this to execute arbitrary code under the context of the user running the webserver.

tags | advisory, remote, web, overflow, arbitrary, cgi
advisories | CVE-2010-1964
SHA-256 | 00278e85899dd283e140d40875be47b96c833e538416bebb14d77122837ee655
Mandriva Linux Security Advisory 2010-117
Posted Jun 17, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-117 - SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which bypasses the validation routine. The updated packages have been patched to correct this issue.

tags | advisory, remote, arbitrary, php, sql injection
systems | linux, mandriva
advisories | CVE-2010-2092
SHA-256 | 33947dbd868524d62aad14623e5a01f9a97ad2142ead8f2fa5b005de44e44224
Ubuntu Security Notice 951-1
Posted Jun 17, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 951-1 - Jun Mao discovered that Samba did not correctly validate SMB1 packet contents. An unauthenticated remote attacker could send specially crafted network traffic that could execute arbitrary code as the root user.

tags | advisory, remote, arbitrary, root
systems | linux, ubuntu
advisories | CVE-2010-2063
SHA-256 | 9507d496c82c755a408def6dfe5c81f2e0e7ea5c2f1f441bf5399a32f62a4db8
Nakid CMS Remote Shell Upload
Posted Jun 17, 2010
Authored by eidelweiss

Nakid CMS suffers from a remote arbitrary shell upload vulnerability.

tags | exploit, remote, arbitrary, shell
SHA-256 | 3c37edb6246cbace20430035a315ff9ae22d896af71f30ebc537d5a9e08696a1
Software Index Remote Shell Upload
Posted Jun 17, 2010
Authored by indoushka

Software Index suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | 2d0067968f0065e97e6da4b306cc5f1d9643146df438c33c200b85a8d992a88c
Software Index Cross Site Scripting
Posted Jun 17, 2010
Authored by indoushka

Software Index suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 3f8fa73529c07bf84ac2ea81d592ef0c41bb636b2075b88f0df22aa8ef27a1ef
PishBini Footbal SQL Injection / Cross Site Scripting
Posted Jun 17, 2010
Authored by indoushka

PishBini Footbal suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | f528163c5facbec463a5fe975ab081208649067eecb13334bd68cbf0c4114b8f
Ceica-GW 1.5 Cross Site Scripting
Posted Jun 17, 2010
Authored by indoushka

Ceica-GW version 1.5 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 1465c6f7ca3bd1bfbadfac886990557c680b6431549f3cd4786a7436ba0287e8
2daybiz Online Classified System SQL Injection / Cross Site Scripting
Posted Jun 17, 2010
Authored by Sid3 effects

2daybiz Online Classified System suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | f6aa481cb1f85f358baa9c8ba71459ccd42b4cd769cd8d6f063d28c16c95c85d
2daybiz Network Community Script SQL Injection / Cross Site Scripting
Posted Jun 17, 2010
Authored by Sid3 effects

2daybiz Network Community Script suffers from cross site scripting and remote SQL injection vulnerabilities.

tags | exploit, remote, vulnerability, xss, sql injection
SHA-256 | b031a3c537dca0cae75bb56471260670a86e6d6d3880971f66b6effda7d9394b
PHPAuctionSystem PHP Code Execution
Posted Jun 17, 2010
Authored by Sid3 effects

PHPAuctionSystem suffers from an arbitrary php code execution vulnerability.

tags | exploit, arbitrary, php, code execution
SHA-256 | 2fc5a1c1f78f4e64119f95a6c9373b94d885bb57728eed2a125535a55280d1e5
AspTR EXtended Cross Site Request Forgery
Posted Jun 17, 2010
Authored by FreWaL

AspTR EXtended suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 79983bfe525c9de9e0e80f93a9a526a48f343fa858a0da177e0206ba704f8bb7
Page 1 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close