what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 15 of 15 RSS Feed

Files Date: 2014-02-21

Stark CRM 1.0 Script Injection / Session Riding
Posted Feb 21, 2014
Authored by LiquidWorm | Site zeroscience.mk

Multiple stored cross site scripting and cross site request forgery vulnerabilities exist when parsing user input to several POST parameters in Stark CRM version 1.0. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site and/or execute arbitrary HTML and script code in a user's browser session.

tags | exploit, web, arbitrary, vulnerability, xss, csrf
SHA-256 | 8c7cb8470dd05d45f08a3c8bf719e35d3641de67c99f53df0cf0f5d685cf33c5
AdRotate 3.9.4 SQL Injection
Posted Feb 21, 2014
Authored by High-Tech Bridge SA | Site htbridge.com

AdRotate version 3.9.4 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
advisories | CVE-2014-1854
SHA-256 | e266028eac942f15f6d5c12f24958ce411494ef2b61a024a7a8ebda861c5fcd0
Hack In The Box Haxpo Call For Papers
Posted Feb 21, 2014
Site haxpo.nl

The HITB crew is calling on the community of hackers, makers, builders, and breakers to send them their 30 minute talk abstracts for consideration to be included in the 3-day single-track agenda. Taking place at De Beurs van Berlage on the 28th, 29th and 30th of May, this single track, like the Haxpo itself, is completely free to attend.

tags | paper, conference
SHA-256 | 5a94102535da35547f397090f1530a04aa901fc426aee761e1b4a5b78ed40e53
Barracuda Networks Web Firewall X300 Cross Site Scripting
Posted Feb 21, 2014
Authored by Benjamin Kunz Mejri, Vulnerability Laboratory | Site vulnerability-lab.com

Barracuda Networks Web Firewall X300 suffers from multiple script insertion vulnerabilities.

tags | exploit, web, vulnerability
SHA-256 | 36ae852bde5cb477c4ae3614c988ae04b0ae0022389592cbd8ba055f726c683f
Egroupware 1.8.005 PHP Object Insertion
Posted Feb 21, 2014
Authored by Pedro Ribeiro

Egroupware versions 1.8.005 and below suffer from a PHP object insertion vulnerability that can allow for arbitrary file deletion and possibly code execution.

tags | exploit, arbitrary, php, code execution
advisories | CVE-2014-2027
SHA-256 | 6acf0c7bb78bf16c4e7a80bf94295df8ed76adf8b9f716ddf1396c8f075f25e8
Lotus Sametime 8.5.1 Password Disclosure
Posted Feb 21, 2014
Authored by Adriano Marcio Monteiro

Verbose logging in Lotus Sametime version 8.5.1 logs a user password simply base64 encoded.

tags | exploit, info disclosure
SHA-256 | 83a7b3d0184d9980f17866ccfef1a87269f5a9bffc36ad1349b83d3f04116a88
Catia V5-6R2013 Stack Buffer Overflow
Posted Feb 21, 2014
Authored by Mohamed Shetta

Dassault Systemes Catia V5-6R2013 "CATV5_Backbone_Bus" stack buffer overflow exploit.

tags | exploit, overflow
SHA-256 | b9c312295d8a073944dc628dace9c57b37d1c0999e861122190110bb6b4e4bd6
VideoCharge Studio 2.12.3.685 MITM Code Execution
Posted Feb 21, 2014
Authored by Julien Ahrens | Site rcesecurity.com

VideoCharge Studio version 2.12.3.685 GetHttpResponse() man in the in middle remote code execution exploit.

tags | exploit, remote, code execution
SHA-256 | 228da2a55f85e238a38f51f0a1e8c982a474297369a89295f5a2d46727406ec5
Slackware Security Advisory - kernel Updates
Posted Feb 21, 2014
Authored by Slackware Security Team | Site slackware.com

Slackware Security Advisory - New kernel packages are available for Slackware 14.1 (64-bit) to fix a security issue.

tags | advisory, kernel
systems | linux, slackware
advisories | CVE-2014-0038
SHA-256 | cc78a9497557a0501a4443b959c390cd7c60c4c627e19be5e2974d83af41c6bd
Gentoo Linux Security Advisory 201402-18
Posted Feb 21, 2014
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory 201402-18 - GNU Midnight Commander does not properly sanitize environment variables, possibly resulting in execution of arbitrary code or Denial of Service. Versions less than 4.8.7 are affected.

tags | advisory, denial of service, arbitrary
systems | linux, gentoo
advisories | CVE-2012-4463
SHA-256 | ceed69737e7c9a4f5f9ef054f685065c8dab8dcda182eaaf2a1e9c196f8826f2
Debian Security Advisory 2865-1
Posted Feb 21, 2014
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2865-1 - Various vulnerabilities were discovered in PostgreSQL.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2014-0060, CVE-2014-0061, CVE-2014-0062, CVE-2014-0063, CVE-2014-0064, CVE-2014-0065, CVE-2014-0066, CVE-2014-0067
SHA-256 | 1e90886f93fefed24a7953c71f5b376443d1842c66045e0c90af12c5d5c348be
Red Hat Security Advisory 2014-0195-01
Posted Feb 21, 2014
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2014-0195-01 - Red Hat JBoss Portal is the open source implementation of the Java EE suite of services and Portal services running atop Red Hat JBoss Enterprise Application Platform. This Red Hat JBoss Portal 6.1.1 release serves as a replacement for 6.1.0.

tags | advisory, java
systems | linux, redhat
advisories | CVE-2013-4517, CVE-2013-6440
SHA-256 | ad17b99c336d1d0ac63117515d8fb941efea61e47e0482fa54c72c275372cd9e
Debian Security Advisory 2864-1
Posted Feb 21, 2014
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2864-1 - Various vulnerabilities were discovered in PostgreSQL.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2014-0060, CVE-2014-0061, CVE-2014-0062, CVE-2014-0063, CVE-2014-0064, CVE-2014-0065, CVE-2014-0066, CVE-2014-0067
SHA-256 | 1867d5a2cd522f7cbb2c54a13eda5771d56c14a038dde227b4ba0af113cc2e61
Mandriva Linux Security Advisory 2014-045
Posted Feb 21, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-045 - A directory traversal attack was reported against libtar, a C library for manipulating tar archives. The application does not validate the filenames inside the tar archive, allowing to extract files in arbitrary path. An attacker can craft a tar file to override files beyond the tar_extract_glob and tar_extract_all prefix parameter. The updated packages have been patched to correct this issue.

tags | advisory, arbitrary
systems | linux, mandriva
advisories | CVE-2013-4420
SHA-256 | a65c1beb056ccb0d18e8a96e55d09be2aa60f9240441e3ae174e13ed63df08d3
Slackware Security Advisory - mariadb, mysql Updates
Posted Feb 21, 2014
Authored by Slackware Security Team | Site slackware.com

Slackware Security Advisory - New mariadb and mysql packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue.

tags | advisory
systems | linux, slackware
advisories | CVE-2014-0001
SHA-256 | b83dbc636a812dc56e004c015b772296ed0b6e308651fe000eca32edf038ccee
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close