Quantcast
Channel: Files Date: 2013-06-10 to 2013-06-11 ≈ Packet Storm
Browsing latest articles
Browse All 16 View Live

ScriptCase SQL Injection

ScriptCase suffers from a remote SQL injection vulnerability.

View Article



Cisco ASA Ethernet Information Leak

This is the Cisco ASA ethernet information leak exploit that leverages the vulnerability noted in CVE-2003-0001. Versions prior to 8.4.4.6 and 8.2.5.32 are affected.

View Article

Concrete5 CMS 5.6.1.2 Cross Site Request Forgery / Cross Site Scripting

Concrete5 CMS version 5.6.1.2 suffers from multiple cross site request forgery and cross site scripting vulnerabilities.

View Article

Debian Security Advisory 2703-1

Debian Linux Security Advisory 2703-1 - Several vulnerabilities were discovered in Subversion, a version control system.

View Article

Debian Security Advisory 2704-1

Debian Linux Security Advisory 2704-1 - It was discovered that applications using the mesa library, a free implementation of the OpenGL API, may crash or execute arbitrary code due to an out of bounds...

View Article


MaxForum 2.0.0 Code Injection / LFI / Disclosure

MaxForum version 2.0.0 suffers from PHP code injection, local file inclusion, and credential disclosure vulnerabilities.

View Article

Lokboard 1.1 PHP Code Injection

Lokboard version 1.1 suffers from a remote PHP code injection vulnerability.

View Article

Sun Java Web Start Double Quote Injection

This Metasploit module exploits a flaw in the Web Start component of the Sun Java Runtime Environment. Parameters intial-heap-size and max-heap-size in a JNLP file can contain a double quote which is...

View Article


NanoBB 0.7 Cross Site Scripting / SQL Injection

NanoBB version 0.7 suffers from cross site scripting and remote SQL injection vulnerabilities.

View Article


Buffalo WZR-HP-G300NH2 Cross Site Request Forgery

Buffalo WZR-HP-G300NH2 suffers from a cross site request forgery vulnerability. The demonstration payload changes the administrative password.

View Article

Weathermap 0.97C Local File Inclusion

Weathermap versions 0.97C and below suffer from a local file inclusion vulnerability.

View Article

Java Applet Driver Manager Privileged toString() Remote Code Execution

This Metasploit module abuses the java.sql.DriverManager class where the toString() method is called over user supplied classes, from a doPrivileged block. The vulnerability affects Java version 7u17...

View Article

Synactis PDF In-The-Box ConnectToSynactic Stack Buffer Overflow

This Metasploit module exploits a vulnerability found in Synactis' PDF In-The-Box ActiveX component, specifically PDF_IN_1.ocx. When a long string of data is given to the ConnectToSynactis function,...

View Article


Exim and Dovecot Insecure Configuration Command Injection

This Metasploit module exploits a command injection vulnerability against Dovecot with Exim using the "use_shell" option. It uses the sender's address to inject arbitrary commands since this is one of...

View Article

Self-Bank Cross Site Scripting

Selfbank.es suffers from multiple cross site scripting vulnerabilities. The author has tried to contact them multiple times but they still have not addressed the issue.

View Article


Ubuntu Security Notice USN-1871-1

Ubuntu Security Notice 1871-1 - Ilja van Sprundel discovered multiple security issues in various X.org libraries and components. An attacker could use these issues to cause applications to crash,...

View Article
Browsing latest articles
Browse All 16 View Live


Latest Images