PDA

View Full Version : Exploits


Pages : [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30

  1. PunBB Mod PunPortal 0.1 Local File Inclusion Exploit
  2. Vuln: AceFTP 'LIST' Command Directory Traversal Vulnerability
  3. Exodus 0.10 (uri handler) Arbitrary Parameter Injection Exploit
  4. Bugtraq: [security bulletin] HPSBMA02388 SSRT080059 rev.1 - HP OpenView Network Node
  5. Bugtraq: Re: Cpanel 11.x Local File Inclusion & Cross Site Scripting - Discovered By
  6. Bugtraq: boastMachine v3.1 Remote Sql Injection
  7. Bugtraq: [ MDVSA-2008:220-1 ] kernel
  8. Vuln: MailEnable IMAP Service Multiple Buffer Overflow Vulnerabilities
  9. Vuln: Roundup XML-RPC Server Security Bypass Vulnerability
  10. AskPert (Auth bypass) Remote SQL Injection Vulnerability
  11. wPortfolio
  12. Pre Job Board (Auth Bypass) Remote SQL Injection Vulnerability
  13. Vuln: Symantec Backup Exec Data Management Protocol Buffer Overflow Vulnerability
  14. Vuln: Mozilla Thunderbird and SeaMonkey 'mailnews' Information Disclosure Vulnerabili
  15. Vuln: Adam Wright HTMLTidy 'html-tidy-logic.php' Cross Site Scripting Vulnerability
  16. Bugtraq: Re: Re: Re: Re: Opera 9.6x file:// overflow
  17. RevSense (Auth bypass) Remote SQL Injection Vulnerability
  18. Vuln: MyTopix 'send' Parameter SQL Injection Vulnerability
  19. Bugtraq: Re: [ MDVSA-2008:232 ] dovecot
  20. Bugtraq: Re: Re: Re: Re: Opera 9.6x file:// overflow
  21. MauryCMS
  22. Vuln: PHPCow Unspecified Remote File Include Vulnerability
  23. Bugtraq: [ MDVSA-2008:232 ] dovecot
  24. Bugtraq: Re: [ MDVSA-2008:231 ] libxml2
  25. Bugtraq: [USN-674-1] HPLIP vulnerabilities
  26. Bugtraq: [SECURITY] [DSA 1667-1] New python2.4 packages fix several vulnerabilities
  27. Bugtraq: rPSA-2008-0325-1 libxml2
  28. MyTopix
  29. Vuln: Microsoft Windows Vista 'iphlpapi.dll' Local Kernel Buffer Overflow Vulnerabili
  30. Bugtraq: PR08-09: Unauthenticated File Retrieval on Sun Java System Identity Manager
  31. Bugtraq: PR07-40: Authentication Bypass, Passwords Leakage and SNMP Injection on 3Com
  32. Vuln: FCKeditor 'connector.php' Arbitrary File Upload Vulnerability
  33. Bugtraq: PR07-11: Cross-site Request Forgery (CSRF) on Sun Java System Identity Manag
  34. Bugtraq: Secunia Research: Streamripper Multiple Buffer Overflows
  35. PunBB (Private Messaging System 1.2.x) Multiple LFI Exploit
  36. Alex Article-Engine 1.3.0 (fckeditor) Arbitrary File Upload Vulnerability
  37. Alex News-Engine 1.5.1 Remote Arbitrary File Upload Vulnerability
  38. Bugtraq: Microsoft VISTA TCP/IP stack buffer overflow
  39. Bugtraq: Metasploit Framework 3.2 Released
  40. Bugtraq: [USN-673-1] libxml2 vulnerabilities
  41. Bugtraq: Firefox cross-domain image theft (CESA-2008-009)
  42. Vuln: IBM Lotus Domino Web Access ActiveX Control Memory Corruption Vulnerabilities
  43. Vuln: MDaemon Server WorldClient Script Injection Vulnerability
  44. Vuln: Ext2 Filesystem Utilities e2fsprogs libext2fs Multiple Unspecified Integer Over
  45. Vuln: Microsoft Internet Explorer 6 RDS.DataControl Denial of Service Vulnerability
  46. Vuln: Mozilla Firefox Arbitrary Image Cross Domain Security Bypass Vulnerability
  47. Vuln: Link Back Checker Cookie Authentication Bypass Vulnerability
  48. Vuln: vBulletin 'admincp/image.php' SQL Injection Vulnerability
  49. Vuln: vBulletin 'admincp/attachmentpermission.php' SQL Injection Vulnerability
  50. Vuln: vBulletin 'admincp/verify.php' SQL Injection Vulnerability
  51. Vuln: vBulletin 'admincalendar.php' SQL Injection Vulnerability
  52. E-topbiz Link Back Checker 1 Insecure Cookie Handling Vulnerability
  53. Free Directory Script 1.1.1 (API_HOME_DIR) RFI Vulnerability
  54. Vuln: RETIRED: Tribiq CMS Cookie Authentication Bypass Vulnerability
  55. Bugtraq: Black Hat November News: CFPS Now Open, Webinar 5 and Japan on-line.
  56. Vuln: Novell eDirectory Multiple Buffer Overflow And Cross-Site Scripting Vulnerabili
  57. Bugtraq: Re: Re: Re: Opera 9.6x file:// overflow
  58. Pluck CMS 4.5.3 (g_pcltar_lib_dir) Local File Inclusion Vulnerability
  59. Vuln: htop Hidden Process Name Input Filtering Vulnerability
  60. Musicbox 2.3.8 (viewalbums.php artistId) SQL Injection Vulnerability
  61. Vuln: No-IP Dynamic Update Client for Linux Remote Buffer Overflow Vulnerability
  62. Bugtraq: Re: Re: Opera 9.6x file:// overflow
  63. Bugtraq: [security bulletin] HPSBST02386 SSRT080164 rev.1 - Storage Management Applia
  64. Bugtraq: Outdated and vulnerable OpenSource libraries used in "Deutsche Telekom" home
  65. Bugtraq: [DSECRG-08-039] Local File Include Vulnerability in Pluck CMS 4.5.3
  66. Vuln: phpFan 'init.php' Remote File Include Vulnerability
  67. Vuln: Jadu Galaxies 'documents.php' SQL Injection Vulnerability
  68. Vuln: SaturnCMS 'Username' Login Page SQL Injection Vulnerability
  69. Bugtraq: [SECURITY] [DSA 1666-1] New libxml2 packages fix several vulnerabilities
  70. Bugtraq: [USN-672-1] ClamAV vulnerability
  71. Bugtraq: [USN-667-1] Firefox and xulrunner vulnerabilities
  72. Bugtraq: [ MDVSA-2008:227-1 ] gnutls
  73. Vuln: Microsoft Communicator RTCP Unspecified Remote Denial of Service Vulnerability
  74. No-IP DUC
  75. CUPS 1.3.7 CSRF (add rss subscription) Remote Crash Exploit
  76. Vuln: Pluck 'g_pcltar_lib_dir' Parameter Local File Include Vulnerability
  77. Vuln: libxml2 'xmlSAX2Characters()' Integer Overflow Vulnerability
  78. Vuln: libxml2 'xmlBufferResize()' Remote Denial of Service Vulnerability
  79. VideoScript
  80. Ultrastats 0.2.144/0.3.11 (index.php serverid) SQL Injection Vulnerability
  81. Vuln: Adobe AIR Unspecified JavaScript Code Execution Vulnerability
  82. Vuln: Chilkat Socket ActiveX 'SaveLastError()' Arbitrary File Overwrite Vulnerability
  83. SaturnCMS (view) Blind SQL Injection Vulnerability
  84. Simple Customer 1.2 (Auth Bypass) SQL Injection Vulnerability
  85. Exodus 0.10 (uri handler) Arbitrary Parameter Injection Vulnerability
  86. Jadu Galaxies (categoryID) Blind SQL Injection Vulnerability
  87. phpfan 3.3.4 (init.php includepath) Remote File Inclusion Vulnerability
  88. Vuln: ActiveCampaign TrioLive 'department_id' SQL Injection and Cross Site Scripting
  89. Vuln: QuadComm Q-Shop Cross Site Scripting and Multiple SQL Injection Vulnerabilities
  90. Vuln: infiniteReality mxCamArchive 'archive/config.ini' Information Disclosure Vulner
  91. Vuln: BoutikOne CMS 'search_query' Parameter Cross Site Scripting Vulnerability
  92. Bugtraq: [USN-671-1] MySQL vulnerabilities
  93. Chilkat Socket activex 2.3.1.1 Remote Arbitrary File Creation Exploit
  94. Vuln: OpenASP 'default.asp' SQL Injection Vulnerability
  95. Vuln: E-Php B2B Trading Marketplace Script 'listings.php' SQL Injection Vulnerability
  96. Vuln: Opera Web Browser 'file://' Heap Based Buffer Overflow Vulnerability
  97. Bugtraq: [waraxe-2008-SA#069] - Multiple Sql Injection in vBulletin 3.7.4
  98. Bugtraq: Exodus v0.10 uri handler arbitrary parameter injection
  99. Bugtraq: Opera 9.6x file:// overflow
  100. Bugtraq: RE: MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]
  101. Vuln: OpenSSH CBC Mode Information Disclosure Vulnerability
  102. Vuln: GungHo LoadPrgAx ActiveX Control Unspecified Vulnerability
  103. Vuln: Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerabil
  104. Bugtraq: rPSA-2008-0321-1 enscript
  105. Vuln: Flosites Blog SQL Injection Vulnerabilities
  106. Vuln: VeryPDF PDFView ActiveX Component Heap Buffer Overflow Vulnerability
  107. Q-Shop 3.0 Remote XSS/SQL Injection Vulnerabilities
  108. FREEze Greetings 1.0 Remote Password Retrieve Exploit
  109. Myiosoft easygallery (catid) Blind SQL Injection Vulnerability
  110. E-topbiz AdManager 4 (group) Blind SQL Injection Vulnerability
  111. OpenASP
  112. mxCamArchive 2.2 Bypass Config Download Vulnerability
  113. Vuln: ClipShare Pro 'channel_detail.php' SQL Injection Vulnerability
  114. Vuln: HOSTNOMI Real Estate Portal Pro 'index.php' SQL Injection Vulnerability
  115. Bugtraq: [waraxe-2008-SA#068] - Sql Injection in vBulletin 3.7.3.pl1
  116. Bugtraq: Microsoft Windows Server Service (MS08-067) Exploit
  117. Bugtraq: ANNOUNCE: RFIDIOt release RFIDIOt-0.1u
  118. Bugtraq: [ GLSA 200811-05 ] PHP: Multiple vulnerabilities
  119. Opera 9.62 file:// Local Heap Overflow Exploit
  120. Vuln: X7 Chat Password Field SQL Injection Vulnerability
  121. Vuln: TurnkeyForms Text Link Sales 'admin.php' SQL Injection and Cross Site Scripting
  122. Bugtraq: Re: [Full-disclosure] MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]
  123. Bugtraq: Re: MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]
  124. Vuln: PHP 'chdir()' and 'ftok()' 'safe_mode' Multiple Security Bypss Vulnerabilities
  125. phpstore Wholesale (track.php?id) SQL Injection Vulnerability
  126. FloSites Blog Multiple Remote SQL Injection Vulnerabilities
  127. MS Windows Server Service Code Execution Exploit (MS08-067) (2k/2k3)
  128. yahoo answers (id) Remote SQL Injection Vulnerability
  129. Minigal b13 (index.php list) Remote File Disclosure Exploit
  130. Sudo
  131. ClipShare Pro 2006-2007 (chid) SQL Injection Vulnerability
  132. Lazarus Guestbook 1.x Insecure Cookie Handling Vulnerability
  133. VeryPDF PDFView OCX ActiveX OpenPDF Heap Overflow PoC
  134. SmbRelay3 NTLM Replay Attack Tool/Exploit (MS08-068)
  135. turnkeyforms Text Link Sales (id) XSS/SQL Injection Vulnerability
  136. X7 Chat 2.0.5 (Auth Bypass) SQL Injection Vulnerability
  137. GS Real Estate Portal Multiple SQL Injection Vulnerability
  138. Vuln: pi3Web ISAPI Directory Remote Denial Of Service Vulnerability
  139. Bugtraq: [ MDVSA-2008:229 ] clamav
  140. Vuln: TurnkeyForms Local Classifieds 'Site_Admin/admin.php' Authentication Bypass Vul
  141. SlimCMS
  142. Bankoi Webhost Panel 1.20 (Auth Bypass) SQL Injection Vulnerability
  143. Vuln: TYPO3 Core Multiple Cross Site Scripting Vulnerabilities
  144. Vuln: Linksys WRT160N DHCP Client Table HTML Injection Vulnerability
  145. Discuz! 6.x/7.x Remote Code Execution Exploit
  146. turnkeyforms Text Link Sales Auth Bypass Vulnerability
  147. GS Real Estate Portal US/International Module Multiple Vulnerabilities
  148. AlstraSoft Web Host Directory 1.2 Multiple Vulnerabilities
  149. Vuln: AlstraSoft SendIt Pro Arbitrary File Upload Vulnerability
  150. Vuln: University of Washington IMAP 'smtp.c' Null Pointer Dereference Denial of Servi
  151. Vuln: Joomla! Simple RSS Reader Component Remote File Include Vulnerability
  152. Vuln: HyperStop WebHost Directory 'admin/login' SQL Injection Vulnerability
  153. Vuln: smcFanControl Local Buffer Overflow Vulnerability
  154. Vuln: Multiple Avira Products Driver IOCTL Request Local Buffer Overflow Vulnerabilty
  155. Bugtraq: Re: A-Link WL54AP3 and WL54AP2 CSRF+XSS vulnerability
  156. Bugtraq: [ MDVSA-2008:228 ] mozilla-firefox
  157. Bugtraq: [USN-670-1] VMBuilder vulnerability
  158. Vuln: Sun Java System Identity Manager Multiple Vulnerabilities
  159. Vuln: OpenOffice 'senddoc' Insecure Temporary File Creation Vulnerability
  160. MemHT Portal 4.0.1 SQL Injection Code Execution Exploit
  161. BandSite CMS 1.1.4 Insecure Cookie Handling Vulnerability
  162. ScriptsFeed (SF) Recipes Listing Portal Remote File Upload Vulnerability
  163. ScriptsFeed (SF) Auto Classifieds Software Remote File Upload Vuln
  164. ScriptsFeed (SF) Real Estate Classifieds Software File Upload Vuln
  165. Vuln: Apple Safari Prior to 3.2 Multiple Security Vulnerabilities
  166. Vuln: Zope PythonScript Multiple Remote Denial Of Service Vulnerabilities
  167. Vuln: Apple Mac OS X ColorSync ICC Profile Remote Buffer Overflow Vulnerability
  168. Vuln: Yosemite Backup 'DtbClsLogin()' Remote Buffer Overflow Vulnerability
  169. Vuln: Sweex RO002 Router Default Password Security Bypass Vulnerability
  170. Vuln: WOW Raid Manager 'auth/auth_phpbb3.php' Security Bypass Vulnerability
  171. Vuln: AJ Classifieds Authentication Bypass Vulnerability
  172. Vuln: AJ Article Authentication Bypass Vulnerabilities
  173. Vuln: AJPoll Security Bypass and SQL Injection Vulnerabilities
  174. Vuln: Google Chrome Pop-Up Address Bar URI Spoofing Vulnerability
  175. Bugtraq: Digital Armaments October-November Hacking Challenge: Linux Local Kernel Exp
  176. Bugtraq: New Whitepaper - .NET Framework Rootkits: Backdoors inside your Framework
  177. Pi3Web
  178. Vuln: WIMS Insecure Temporary File Creation Vulnerabilities
  179. Vuln: AJ Auction Pro Authentication Bypass Vulnerabilities
  180. Vuln: FreshScripts Fresh Email Script Session Fixation and Remote File Include Vulner
  181. Vuln: Multiple phpstore.info Scripts Arbitrary File Upload Vulnerability
  182. Vuln: rtgdictionary for TYPO3 Arbitrary File Upload Vulnerability
  183. Bugtraq: Team SHATTER Security Advisory: Oracle Database Multiple SQL Injection vulne
  184. Bugtraq: Team SHATTER Security Advisory: Oracle Database multiple SQL Injection vulne
  185. Bugtraq: Team SHATTER Security Advisory: Oracle Database SQL Injection in SYS.DBMS_CD
  186. Bugtraq: Team SHATTER Security Advisory: Oracle Database SQL Injection in SYS.DBMS_CD
  187. Bugtraq: [ MDVSA-2008:227 ] gnutls
  188. Vuln: Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities
  189. turnkeyforms Web Hosting Directory Multiple Vulnerabilities
  190. turnkeyforms Local Classifieds Auth Bypass Vulnerability
  191. Vuln: Free simple PHP guestbook 'act.php' Arbitrary Script Injection Vulnerability
  192. Vuln: OptiPNG BMP Reader Buffer Overflow Vulnerability
  193. Vuln: Dizi Portali 'film.asp' SQL Injection Vulnerability
  194. Vuln: x10 Automatic MP3 Script 'url' Parameter File Disclosure Vulnerability
  195. Vuln: Cyberfolio 'theme' Parameter Local File Include Vulnerability
  196. Vuln: Joomla! JooBlog Component 'PostID' Parameter SQL Injection Vulnerability
  197. Vuln: Zeeways ZEEJOBSITE Arbitrary File Upload Vulnerability
  198. Vuln: initscripts Arbitrary File Deletion Vulnerability
  199. Vuln: UltraVNC VNCViewer 'FileTransfer.cpp' Multiple Remote Buffer Overflow Vulnerabi
  200. Bugtraq: rPSA-2008-0316-1 kernel
  201. Bugtraq: [SECURITY] [DSA 1665-1] New libcdaudio packages fix arbitrary code execution
  202. Bugtraq: rPSA-2008-0318-1 initscripts
  203. Vuln: Zeeways PHOTOVIDEOTUBE 'admin/home.php' Authentication Bypass Vulnerability
  204. Vuln: Zeeways SHAADICLONE 'admin/home.php' Authentication Bypass Vulnerability
  205. Bugtraq: rPSA-2008-0315-1 net-snmp net-snmp-client net-snmp-server net-snmp-utils
  206. Bugtraq: Re: Re: MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]
  207. Quick Poll Script (code.php id) Remote SQL Injection Vulnerability
  208. MS Windows Server Service Code Execution Exploit (MS08-067)
  209. Vuln: Mole Group Airline Ticket Script 'username' SQL Injection Vulnerability
  210. Vuln: Multiple V3 Chat Products Cookie Authentication Bypass Vulnerability
  211. Vuln: TYPO3 advCalendar Extension Unspecified SQL Injection Vulnerability
  212. Vuln: TYPO3 CMS Poll system Extension Unspecified SQL Injection Vulnerability
  213. AlstraSoft Web Host Directory (Auth Bypass) SQL Injection Vuln
  214. AlstraSoft Article Manager Pro (Auth Bypass) SQL Injection Vuln
  215. AlstraSoft SendIt Pro Remote File Upload Vulnerability
  216. Vuln: Joomla! and Mambo Catalog Production Component 'id' Parameter SQL Injection Vul
  217. Vuln: Digiappz DigiAffiliate Script SQL Injection Vulnerabilities
  218. Vuln: Retired: Microsoft November 2008 Advance Notification Multiple Vulnerabilities
  219. Vuln: Retired: Microsoft October 2008 Advance Notification Multiple Vulnerabilities
  220. Bugtraq: [security bulletin] HPSBMA02385 SSRT080161 rev.1 - HP Service Manager (HPSM)
  221. Vuln: MemHT Portal 'lang/english.php' SQL Injection Vulnerability
  222. Vuln: MoinMoin Cross-Site Scripting and Information Disclosure Vulnerabilities
  223. Net-SNMP
  224. Castle Rock Computing SNMPc < 7.1.1 (Community) Remote BOF PoC
  225. Vuln: RETIRED: Savvy Content Manager Multiple Cross Site Scripting Vulnerabilities
  226. Vuln: Joomla! and Mambo com_marketplace Component 'catid' Parameter SQL Injection Vul
  227. Vuln: Trend Micro ServerProtect Multiple Remote Vulnerabilities
  228. PozScripts Business Directory Script (id) Remote SQL Injection Vuln
  229. Joomla Component com_marketplace 1.3.1 (catid) SQL Injection Vuln
  230. Joomla Component Simple RSS Reader 1.0 RFI Vulnerability
  231. Vuln: Microsoft XML Core Services Transfer Encoding Cross Domain Information Disclosu
  232. Vuln: Microsoft XML Core Services DTD Cross Domain Information Disclosure Vulnerabili
  233. Vuln: Pre Real Estate Listings 'login.php' Multiple SQL Injection Vulnerabilities
  234. Bugtraq: [USN-669-1] gnome-screensaver vulnerabilities
  235. Joomla/ Mambo com_catalogproduction (id) SQL Injection Vulnerability
  236. Vuln: GnuTLS X.509 Certificate Chain Security Bypass Vulnerability
  237. Vuln: Microsoft XML Core Services Race Condition Memory Corruption Vulnerability
  238. Vuln: Microsoft Windows SMB Credential Reflection Vulnerability
  239. Pre Real Estate Listings File Upload Vulnerability
  240. Joomla Component Contact Info 1.0 SQL Injection Vulnerability
  241. Joomla Component com_books (book_id) SQL Injection Vulnerability
  242. Bugtraq: ooVoo 1.7.1.35 (URL Protocol) remote unicode buffer overflow poc
  243. Bugtraq: [security bulletin] HPSBMA02380 SSRT080121 rev.2 - HP System Management Home
  244. Bugtraq: Joomla Component JooBlog 0.1.1 (PostID) SQL Injection Vuln.
  245. Bugtraq: Google Chrome Break
  246. Vuln: Linux Kernel '__scm_destroy()' Local Denial of Service Vulnerability
  247. Linux Kernel < 2.4.36.9/2.6.27.5 Unix Sockets Local Kernel Panic Exploit
  248. ooVoo 1.7.1.35 (URL Protocol) Remote Unicode Buffer Overflow PoC
  249. Aj Classifieds Authentication Bypass Vulnerability
  250. smcFanControl 2.1.2 Multiple Buffer Overflow Vulnerabilities PoC (OSX)