exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 15 of 15 RSS Feed

Files Date: 2013-08-13

Red Hat Security Advisory 2013-1156-01
Posted Aug 13, 2013
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2013-1156-01 - The Apache HTTP Server is a popular web server. A flaw was found in the way the mod_dav module of the Apache HTTP Server handled merge requests. An attacker could use this flaw to send a crafted merge request that contains URIs that are not configured for DAV, causing the httpd child process to crash. All httpd users should upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the updated packages, the httpd daemon will be restarted automatically.

tags | advisory, web
systems | linux, redhat
advisories | CVE-2013-1896
SHA-256 | c17175cfabd50dd9b555b366ee3d4d54b0838e4eda7127362bf401fe4f1ac034
Mandriva Linux Security Advisory 2013-213
Posted Aug 13, 2013
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2013-213 - A security vulnerability has been found in version 4.x of the Xymon Systems and Network Monitor tool. The error permits a remote attacker to delete files on the server running the Xymon trend-data daemon xymond_rrd. File deletion is done with the privileges of the user that Xymon is running with, so it is limited to files available to the userid running the Xymon service. This includes all historical data stored by the Xymon monitoring system.

tags | advisory, remote
systems | linux, mandriva
advisories | CVE-2013-4173
SHA-256 | 2d6575b2d17685e51b1feb90665a241df32c9b4eb72d5465d1f0f735b4a1d6c8
Red Hat Security Advisory 2013-1155-01
Posted Aug 13, 2013
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2013-1155-01 - VDSM is a management module that serves as a Red Hat Enterprise Virtualization Manager agent on Red Hat Enterprise Virtualization Hypervisor or Red Hat Enterprise Linux hosts. It was found that the fix for CVE-2013-0167 released via RHSA-2013:0886 was incomplete. A privileged guest user could potentially use this flaw to make the host the guest is running on unavailable to the management server. This issue was found by David Gibson of Red Hat.

tags | advisory
systems | linux, redhat
advisories | CVE-2013-4236
SHA-256 | a311e8b49848718d0993bccd584c293b9d923bb4c8a03ba60c49ff49d46f5b42
Mandriva Linux Security Advisory 2013-212
Posted Aug 13, 2013
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2013-212 - It was discovered that otrs2, the Open Ticket Request System, does not properly sanitise user-supplied data that is used on SQL queries. An attacker with a valid agent login could exploit this issue to craft SQL queries by injecting arbitrary SQL code through manipulated URLs.

tags | advisory, arbitrary
systems | linux, mandriva
advisories | CVE-2013-4717
SHA-256 | 5ecc1971b7c3965a30dc10ac0ddd13fa0f59ca6dda6e9dce200dc16ec8e33b23
Microsoft Security Bulletin Summary For August, 2013
Posted Aug 13, 2013
Site microsoft.com

This bulletin summary lists 8 released Microsoft security bulletins for August, 2013.

tags | advisory
SHA-256 | 675a988404633a70907f884dd623b6aa2fb4cd12759adb87a44adeaf8176488e
Struts2 2.3.15 OGNL Injection
Posted Aug 13, 2013
Authored by Takeshi Terada

Struts2 suffers from an OGNL injection vulnerability that allows for redirection. Versions 2.0.0 through 2.3.15 are affected.

tags | exploit
advisories | CVE-2013-2251
SHA-256 | 8dd8aee0be9f1818cac60e7eaadec5a677b61944590e6c481865994fb69abbf0
CakePHP 2.3.7 / 2.2.8 Local File Inclusion
Posted Aug 13, 2013
Authored by Takeshi Terada

CakePHP versions 2.3.7 and 2.2.8 suffer from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 92c71209b2cf74bbca5dffab287435b8882d6cd95365ae3008c5330a8b79f357
MinaliC Webserver 2.0.0 Buffer Overflow
Posted Aug 13, 2013
Authored by PuN1sh3r

MinaliC Webserver version 2.0.0 buffer overflow exploit with egg-hunting shellcode.

tags | exploit, overflow, shellcode
SHA-256 | 0e6dd9ada1044d6bc5665d1aeacad35857c407d2de169610d6fdce8cfe13e5ad
DotNetNuke (DNN) 7.1.0 / 6.2.8 Cross Site Scripting
Posted Aug 13, 2013
Authored by Sajjad Pourali, Nasser Salim Al-Hadhrami

DotNetNuke (DNN) versions prior to 7.1.0 and 6.2.8 suffer from a cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2013-4649
SHA-256 | d5fce71c870f5c7156d287f5104511526b84a26432231c7c2bdefd7c00f5a00e
Microsoft Security Bulletin Re-Release For August, 2013
Posted Aug 13, 2013
Site microsoft.com

This bulletin summary lists three re-released Microsoft security bulletins for August, 2013.

tags | advisory
SHA-256 | d923728f628cf440baaee3dd5356e47974e02e9e298e70645af9e96fafb88897
ZeroShell 2.0RC2 File Disclosure / Command Execution
Posted Aug 13, 2013
Authored by Yann CAM

ZeroShell version 2.0RC2 suffers from remote command execution and file disclosure vulnerabilities.

tags | exploit, remote, vulnerability, info disclosure
SHA-256 | a3301b1b1b854ed7a03d68ac3c2b4962977e82f6b314949e717334f8076016a4
I2P 0.9.7.1
Posted Aug 13, 2013
Authored by welterde | Site i2p2.de

I2P is an anonymizing network, offering a simple layer that identity-sensitive applications can use to securely communicate. All data is wrapped with several layers of encryption, and the network is both distributed and dynamic, with no trusted parties. This is the source code release version.

Changes: 0.9.4 includes a fix for a network capacity bug, introduced in 0.9.2, which was reducing network performance and reliability. It also includes major changes in the in-network update system, and adds the capability to update via in-network torrents. It fixes several bugs in the i2psnark DHT implementation which was introduced in the last release. For those of you using console or HTTP proxy passwords, it converts to the more-secure digest method and improves the security for console forms.
tags | tool
systems | unix
SHA-256 | 7b73bdb23c53798054741cbaa4e7d8cce832ee566fbb17df0c803d0c22d099e1
Struts2 2.3.15 Open Redirect
Posted Aug 13, 2013
Authored by Takeshi Terada

Struts2 suffers from an open redirection vulnerability. Versions 2.0.0 through 2.3.15 are affected.

tags | exploit
advisories | CVE-2013-2248
SHA-256 | 8e587d23a0336a32690f4388769b814ac267b69bb258b88ffb28d65bb7e874dc
Mac's CMS 1.1.4 CSRF / XSS / Path Disclosure
Posted Aug 13, 2013
Authored by Yashar shahinzadeh

Mac's CMS version 1.1.4 suffers from cross site request forgery, cross site scripting, and path disclosure vulnerabilities.

tags | exploit, vulnerability, xss, info disclosure, csrf
SHA-256 | 55860ccb862ac3230ea90978d0c9a0651d8fbde8b1659a56b2b92a96e6e5b1f5
onehttpd 0.7 Denial Of Service
Posted Aug 13, 2013
Authored by superkojiman

onehttpd version 0.7 suffers from a denial of service vulnerability.

tags | exploit, denial of service
SHA-256 | 343b4e9dc058a440e6e7540a36fe630a737e8fac45a599427e1c9b761ff57062
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close