Section: .. / 0907-exploits /
| /// File Name: |
american-lfi.txt |
Description:
|
American Airlines' sites suffer from a local file inclusion vulnerability. The author was ignored when contacting them so this is being published.
| | Author: | Bob Smith | | File Size: | 4440 | | Last Modified: | Jul 17 15:20:18 2009 |
| MD5 Checksum: | 1952b1b96867b27ab3f4f09fb040be8e |
|
| /// File Name: |
apw-sql.txt |
Description:
|
The site at www.autopartswarehouse.com suffers from a remote SQL injection vulnerability. The owner of the site was notified and ignored the person reporting the vulnerability to them.
| | Author: | Gm0 | | File Size: | 2264 | | Last Modified: | Jul 14 15:26:54 2009 |
| MD5 Checksum: | 60af14449b42fe988378142d66e1bb0a |
|
| /// File Name: |
articlepubpro-sql.txt |
Description:
|
Article Publisher PRO version 2.0.3 suffers from a remote SQL injection vulnerability.
| | Author: | MizoZ | | File Size: | 1194 | | Last Modified: | Jul 29 15:13:45 2009 |
| MD5 Checksum: | 8e0298ca5e5260cfb58db39564cb0b8a |
|
| /// File Name: |
ashop-disclose.txt |
Description:
|
AShop version ru.1.Beta suffers from a remote database configuration disclosure vulnerability.
| | Author: | Septemb0x | | Homepage: | http://www.cyber-warrior.org/ | | File Size: | 1212 | | Last Modified: | Jul 22 17:07:21 2009 |
| MD5 Checksum: | bfe67485f7e8e5e02c37d00b3cbebd43 |
|
| /// File Name: |
astrology-xss.txt |
Description:
|
Astrology suffers from a cross site scripting vulnerability.
| | Author: | Moudi | | File Size: | 2066 | | Last Modified: | Jul 20 13:38:55 2009 |
| MD5 Checksum: | 1fa2c02510b75fdf7db526e5f7f1ba0d |
|
| /// File Name: |
atapanic.c |
Description:
|
Local denial of service kernel panic exploit for FreeBSD versions 6 and 8 that takes advantage of the ata device.
| | Author: | Shaun Colley | | File Size: | 1164 | | Last Modified: | Jul 13 17:11:14 2009 |
| MD5 Checksum: | c6e6b900f7e592f97dbba9bd92310611 |
|
| /// File Name: |
audioplus-overflow.txt |
Description:
|
AudioPLUS version 2.00.215 local buffer overflow exploit that creates a malicious .m3u file.
| | Author: | HACK4LOVE | | File Size: | 2058 | | Last Modified: | Jul 1 12:49:42 2009 |
| MD5 Checksum: | 75e242955815f146d9e1cda68fa47037 |
|
| /// File Name: |
audioplus-overwrite.txt |
Description:
|
AudioPLUS version 2.00.215 SEH overwrite exploit that creates a malicious .m3u file.
| | Author: | Stack | | Homepage: | http://v4-team.com/ | | File Size: | 2105 | | Last Modified: | Jul 15 11:16:04 2009 |
| MD5 Checksum: | c35c59ee588d491f3236990088aa01bb |
|
| /// File Name: |
audiopluspls-overflow.txt |
Description:
|
AudioPLUS version 2.00.215 local buffer overflow exploit that creates a malicious .pls file.
| | Author: | Stack | | Homepage: | http://v4-team.com/ | | File Size: | 1889 | | Last Modified: | Jul 2 01:37:46 2009 |
| MD5 Checksum: | 1d692d9221ce1f45936a45443c3afe65 |
|
| /// File Name: |
avax13-dos.txt |
Description:
|
Avax Vector Active-X control version 1.3 proof of concept denial of service exploit that takes advantage of avPreview.ocx.
| | Author: | Satan_Hackers | | File Size: | 705 | | Last Modified: | Jul 6 13:34:25 2009 |
| MD5 Checksum: | 02e52e629c86683fa5d1d83cae3e1dbd |
|
| /// File Name: |
awcm-lfibypass.txt |
Description:
|
AWCM version 2.1 suffers from local file inclusion and remote SQL injection vulnerabilities. The SQL injection vulnerability allows for authentication bypass.
| | Author: | SwEET-DeViL | | File Size: | 3132 | | Last Modified: | Jul 23 13:05:36 2009 |
| MD5 Checksum: | 37f779a97d8a2377aa1ae91eab0e15b5 |
|
| /// File Name: |
awingsoftweb3d-overflow.txt |
Description:
|
AwingSoft Web3D Player using WindsPly.ocx versions 3.5.0.0 and below suffer from a remote buffer overflow vulnerability in SceneURL().
| | Author: | shinnai | | Homepage: | http://shinnai.altervista.org/ | | File Size: | 1289 | | Last Modified: | Jul 13 11:38:48 2009 |
| MD5 Checksum: | 5bfc5135f6abcdc19b3b73c34c9d6509 |
|
| /// File Name: |
axesstel-bypass.txt |
Description:
|
The Axesstel MV 410R protects from malicious input by leveraging javascript, allowing an attacker to bypass all of this easily. The device is also susceptible to permanent cross site scripting vulnerabilities.
| | Author: | Filip Palian | | File Size: | 3879 | | Last Modified: | Jul 3 11:32:15 2009 |
| MD5 Checksum: | 3b3cb74b779b5512da641e7061b101b6 |
|
| /// File Name: |
b374-desc |
Description:
|
Unavailable.
| | File Size: | 355 | | Last Modified: | Mar 26 14:23:45 2009 |
| MD5 Checksum: | 6bee6f138cfb9ee1789a0ca8cb56d96d |
|
| /// File Name: |
basilic-sql.txt |
Description:
|
Basilic version 1.5.13 suffers from a remote SQL injection vulnerability.
| | Author: | NoGe | | File Size: | 1353 | | Last Modified: | Jul 24 14:28:36 2009 |
| MD5 Checksum: | afc0e3207dd186075630b1a011592cee |
|
| /// File Name: |
basilic-xss.txt |
Description:
|
Basilic CMS version 1.5.13 suffers from a cross site scripting vulnerability.
| | Author: | PLATEN | | File Size: | 689 | | Last Modified: | Jul 27 20:46:10 2009 |
| MD5 Checksum: | 93fcf9c67f5f2904882c53de4342ab37 |
|
| /// File Name: |
battleblog125-sql.txt |
Description:
|
Battle Blog version 1.25 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
| | Author: | SqL_DoCt0r | | Related Exploit: | battleblog-sql.txt | | File Size: | 1199 | | Last Modified: | Jul 17 17:13:02 2009 |
| MD5 Checksum: | 311f635ae175637923156d66d41bc2e7 |
|
| /// File Name: |
bes-sql.txt |
Description:
|
Banner Exchange Script version 1.0 suffers from a remote blind SQL injection vulnerability.
| | Author: | 599eme Man | | File Size: | 1935 | | Last Modified: | Jul 30 13:06:43 2009 |
| MD5 Checksum: | 69b023b21c8644958ac8aa061b46d7e5 |
|
| /// File Name: |
bigsister-disclose.txt |
Description:
|
Big Sister File Exchange Server version 0.03 suffers from a database configuration disclosure vulnerability.
| | Author: | Septemb0x | | Homepage: | http://www.cyber-warrior.org/ | | File Size: | 1043 | | Last Modified: | Jul 8 12:35:56 2009 |
| MD5 Checksum: | 639cebe7f47d1b8e12cbabc28dbe83e0 |
|
| /// File Name: |
bind.c |
Description:
|
ISC BIND 9 remote dynamic update message denial of service proof of concept exploit.
| | Author: | Kingcope | | File Size: | 3708 | | Related CVE(s): | CVE-2009-0696 | | Last Modified: | Jul 30 11:50:06 2009 |
| MD5 Checksum: | a61bbabebb2a6b7d45a77e10bf8e5b8e |
|
| /// File Name: |
cakephp-lfi.txt |
Description:
|
CakePHP version 1.1.20 suffers from a local file inclusion vulnerability.
| | Author: | Cru3l.b0y | | Homepage: | http://www.deltahacking.ir/ | | File Size: | 1822 | | Last Modified: | Jul 6 14:38:08 2009 |
| MD5 Checksum: | 75f433c22b17ba9ba2328df4da2a713a |
|
|
|
|
|