Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

Packet Storm Security Exploits

Syndicate content
Packet Storm Last 10 Exploits
Updated: 2 weeks 1 day ago

ogmenu-xss.txt

Thu, 07/15/2010 - 19:03
Drupal version 6.16 with OG Menu version 6.x-2.0 suffers from a cross site scripting vulnerability.
Categories: Exploits

adnetwork-xss.txt

Thu, 07/15/2010 - 19:03
Ad Network Script suffers from a cross site scripting vulnerability.
Categories: Exploits

simpgb-xss.txt

Thu, 07/15/2010 - 19:03
SimpGB versions 1.37.3 and below suffer from a cross site scripting vulnerability.
Categories: Exploits

msexcel0x5d-overflow.txt

Thu, 07/15/2010 - 19:03
Microsoft Excel 0x5D record stack overflow exploit.
Categories: Exploits

zenphoto-xsrf.txt

Thu, 07/15/2010 - 19:03
Zenphoto CMS version 1.3 suffers from multiple cross site request forgery vulnerabilities.
Categories: Exploits

PR09-16.txt

Thu, 07/15/2010 - 19:03
Procheckup has found by making a malformed request to the Juniper IVE Web interface without authentication, that a vanilla cross site scripting (XSS) attack is possible.
Categories: Exploits

2daybizbc-sql.txt

Thu, 07/15/2010 - 19:03
2daybiz Businesscard Script suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Categories: Exploits

weblogic-inject.txt

Thu, 07/15/2010 - 19:03
Virtual Security Research, LLC. Security Advisory - Over the last several years, VSR analysts had observed unusual behavior in multiple WebLogic deployments when certain special characters were URL encoded and appended to URLs. In late April, 2010 VSR began researching this more in depth and found that the issue could allow for HTTP header injection and HTTP request smuggling attacks.
Categories: Exploits

arora-dos.txt

Thu, 07/15/2010 - 19:03
Arora Browser version 0.10.0-1 remote denial of service exploit.
Categories: Exploits

diferiorcms-xsrf.txt

Thu, 07/15/2010 - 19:03
Diferior CMS version 8.01 suffers from multiple cross site request forgery vulnerabilities.
Categories: Exploits

struts2xwork-exec.txt

Wed, 07/14/2010 - 15:49
Struts2/XWork suffers from a remote command execution vulnerability.
Categories: Exploits

joomlaqcontacts-sql.txt

Wed, 07/14/2010 - 15:49
The Joomla QContacts component suffers from a remote SQL injection vulnerability.
Categories: Exploits

ajarticle-xss.txt

Wed, 07/14/2010 - 15:49
AJ Article suffers from a persistent cross site scripting vulnerability.
Categories: Exploits

customcms-xss.txt

Wed, 07/14/2010 - 15:49
CustomCMS suffers from a persistent cross site scripting vulnerability.
Categories: Exploits

asxtomp3-seh.txt

Wed, 07/14/2010 - 15:49
ASX to MP3 Converter version 3.1.2.1 SEH exploit with DEP and ASLR bypass for multiple OSes.
Categories: Exploits

ms10_042_helpctr_xss_cmd_exec.rb.txt

Wed, 07/14/2010 - 15:49
Help and Support Center is the default application provided to access online documentation for Microsoft Windows. Microsoft supports accessing help documents directly via URLs by installing a protocol handler for the scheme hcp . Due to an error in validation of input to hcp:// combined with a local cross site scripting vulnerability and a specialized mechanism to launch the XSS trigger, arbitrary command execution can be achieved. On IE7 on XP SP2 or SP3, code execution is automatic. If WMP9 is installed, it can be used to launch the exploit automatically. If IE8 and WMP11, either can be used to launch the attack, but both pop dialog boxes asking the user if execution should continue. This exploit detects if non-intrusive mechanisms are available and will use one if possible. In the case of both IE8 and WMP11, the exploit defaults to using an iframe on IE8, but is configurable by setting the DIALOGMECH option to none or player .
Categories: Exploits

diem-xss.txt

Wed, 07/14/2010 - 15:49
Diem version 5.1.2 suffers from multiple cross site scripting vulnerabilities.
Categories: Exploits

inetem-sql.txt

Wed, 07/14/2010 - 00:58
I-net Enquiry Management Script suffers from a remote SQL injection vulnerability.
Categories: Exploits

ari-lfixsrfxss.txt

Wed, 07/14/2010 - 00:58
Asterisk Recording Interface suffers from cross site request forgery, cross site scripting, denial of service, local file inclusion and path disclosure vulnerabilities.
Categories: Exploits

orbis-xsrf.txt

Wed, 07/14/2010 - 00:58
Orbis CMS version 1.0.2 suffers from multiple cross site request forgery vulnerabilities.
Categories: Exploits

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.