|
Colapse all |
Post message
Techno Dreams FAQ Manager Package v1.0(faqview.asp) Remote SQL Injection Vulnerability 2006-09-17 ajannhwt hotmail com Charon Cart v3(Review.asp) Remote SQL Injection Vulnerability 2006-09-17 ajannhwt hotmail com Vulnerability Report ************************************************************************ ******* # Title : Charon Cart v3(Review.asp) Remote SQL Injection Vulnerability # Author : ajann # Script Page : http://www.charon.co.uk # Exploit; ***************************************** [ more ] [ reply ] USB Attacks Going Commercial? 2006-09-18 Gadi Evron (ge linuxbox org) In the public hacking world, so far we have mostly seen USB technology from security vendors... not the attackers side. A few years ago we had discussions on pen-test (http://archives.neohapsis.com/archives/sf/pentest/2004-06/thread.html#2 ), and later bugtraq and FD on these risks, following an art [ more ] [ reply ] Q-Shop v3.5(browse.asp) Remote SQL Injection Vulnerability 2006-09-17 ajannhwt hotmail com Vulnerability Report ************************************************************************ ******* # Title : Q-Shop v3.5(browse.asp) Remote SQL Injection Vulnerability # Author : ajann # Script Page : http://quadcomm.com # Exploit; ************************************************ [ more ] [ reply ] MyBB 1.2 Full path and Cross site scripting vulnerabilities 2006-09-17 security soqor net Hello Title : MyBB 1.2 Full path and Cross site scripting vulnerabilities Discovered by : HACKERS PAL Copyrights : HACKERS PAL Website : WwW.SoQoR.NeT Email : security (at) soqor (dot) net [email concealed] Full path inc/generic_error.php?message=1 inc/datahandlers/event.php inc/datahandlers/pm.php inc/datahandler [ more ] [ reply ] [USN-348-1] GnuTLS vulnerability 2006-09-18 Martin Pitt (martin pitt canonical com) =========================================================== Ubuntu Security Notice USN-348-1 September 18, 2006 gnutls11, gnutls12 vulnerability CVE-2006-4790 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.04 Ub [ more ] [ reply ] PhotoPost PHP 4.6 - 4.5 [PP_PATH] >> Remote File Include Vulnerability 2006-09-18 AG- Spider (ag-spider msn com) ######################################################################## ############## # # PhotoPost PHP 4.6 - 4.5 [PP_PATH] >> Remote File Include Vulnerability # ######################################################################## ############## # Found by ..........: AG-Spider # [ more ] [ reply ] EShoppingPro v1.0(search_run.asp) Remote SQL Injection Vulnerability 2006-09-17 ajannhwt hotmail com Vulnerability Report ************************************************************************ ******* # Title : EShoppingPro v1.0(search_run.asp) Remote SQL Injection Vulnerability # Author : ajann # Script Page : http://www.keyvan1.com # Exploit; *********************************** [ more ] [ reply ] McAfee VirusScan Enterprise - disabling the client side "On-Access Scan" 2006-09-15 EitanCaspi (at) yahoo (dot) com [email concealed] (eitancaspi yahoo com) Suggested Risk Level: Low Type of Risk: Disabling security component. Affected Software: VirusScan Enterprise 7.1.0 (client side, managed centrally by ePolicy Orchestrator), Scan Engine: 4.4.00, the "VirusScan On-Access Scan" component. OS Environment: Windows 2000 workstation w/SP4 and all the [ more ] [ reply ] HitWeb v3.0 - Remote File Include Vulnerabilities 2006-09-15 erne ernealizm com # ERNE ---- ERNEALiZM ---- BU ASK BiTMEZ---- # HitWeb v3.0 - Remote File Include Vulnerabilities # site : http://www.comscripts.com/jump.php?action=script&id=12 # Script : HitWeb v3.0 # Credits : ERNE # Contact : erne (at) ernealizm (dot) com [email concealed] and irc.gigachat.net #kurdhack # Tha [ more ] [ reply ] Limbo - Lite Mambo CMS Multiple Vulnerabilities 2006-09-13 security soqor net Hello Title : Limbo - Lite Mambo CMS Multiple Vulnerabilities (Remote File including - Full path - make php shell - and create folder with 0777 permissions) Discovered by : HACKERS PAL Copyrights : HACKERS PAL Website : WwW.SoQoR.NeT Email : security (at) soqor (dot) net [email concealed] /************************** [ more ] [ reply ] Re: Fwd: IE ActiveX 0day? 2006-09-15 Juha-Matti Laurio (juha-matti laurio netti fi) The following references are available too: SANS ISC: http://isc.sans.org/diary.php?storyid=1701 http://isc.sans.org/diary.php?storyid=1705 Microsoft Security Advisory #925444: http://www.microsoft.com/technet/security/advisory/925444.mspx US-CERT VU#377369: http://www.kb.cert.org/vuls/id/377369 [ more ] [ reply ] rPSA-2006-0169-1 firefox thunderbird 2006-09-15 rPath Update Announcements (announce-noreply rpath com) rPath Security Advisory: 2006-0169-1 Published: 2006-09-15 Products: rPath Linux 1 Rating: Severe Exposure Level Classification: Indirect User Deterministic Unauthorized Access Updated Versions: firefox=/conary.rpath.com@rpl:devel//1/1.5.0.7-0.1-1 thunderbird=/conary.rpath.com@rpl:devel/ [ more ] [ reply ] [Reversemode Advisory] Apple Quicktime FLIC File Heap Overflow 2006-09-15 Reversemode (advisories reversemode com) Hi, Apple Quicktime <= 7.1 is prone to a heap overflow vulnerability. This flaw could lead to a remote code execution,if an attacker tricks the victim to visit a malicious webpage with a specially crafted .fli animation embedded. The flaw is located within the "COLOR_64 chunk" Quicktime parser. [ more ] [ reply ] Roller Weblogger XSS vulnerability 2006-09-15 p3rlhax gmail com I. BACKGROUND Roller is the open source blog server that drives Sun Microsystem's blogs.sun.com employee blogging site, IBM DeveloperWorks blogs, thousands of internal blogs at IBM Blog Central, the Javalobby's 10,000 user strong JRoller Java community site, and hundreds of other blogs world- [ more ] [ reply ] BolinOS v.4.5.5 <= (gBRootPath) Remote File Include Vulnerability 2006-09-15 x0r0n hotmail com =-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-= =-==-= + +BolinOS v.4.5.5 <= (gBRootPath) Remote File Include Vulnerability + =-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-= =-==-= + +Author: xoron (turkish hacker) + =-==-==-==-==-==-==-==-==-= [ more ] [ reply ] phpQuiz sensitive file (install.php) 2006-09-15 sn_0py hotmail com * phpQuiz sensitive file (install.php without authentification) + Files containing interesting info (passwords for sql db) * By : sn0oPy * Risk : verry high * Site : http://phpquiz.com/ * Dork : intitle:"phpQuiz" | " Développé par PhpQuiz v.1.0 " | "© PhpQuiz" | inurl:"PhpQuiz" * exp [ more ] [ reply ] Symantec Norton Insufficient validation of 'SymEvent' driver input buffer 2006-09-15 David Matousek (david matousec com) Hello, I would like to inform you about a vulnerability in Norton Personal Firewall. Description: Norton insufficiently protects its driver '\Device\SymEvent' against a manipulation by malicious applications and it fails to validate its input buffer. It is possible to open this driver and send [ more ] [ reply ] Mambo com_serverstat Component <=0.4.4 Remote File Include Vulnerability 2006-09-14 x0r0n hotmail com =-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-= =-==-= + +Mambo com_serverstat Component <=0.4.4 Remote File Include Vulnerability + =-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-==-= =-==-= + +Author: xoron (turkish hacker) + =-==-==-==-==-==-==- [ more ] [ reply ] SolpotCrew Advisory #10 - phpBB XS (phpbb_root_path) Remote File Include 2006-09-15 jong_amq hotmail com @System Security Meeting in Pisa 2006-09-15 Giorgio Zoppi (zoppi cli di unipi it) The IT Association @System http://www.atsystem.org is organizing the 4th edition of the Convention on IT Security "Net&System Security" which will be held at the Auditorium of Pisaâ??s CNR on October 17, 2006. The event is being organized in collaboration with and coordination of representatives of [ more ] [ reply ] SolpotCrew Advisory #11 - ReviewPost 2.5 (RP_PATH) Remote File Inclusion 2006-09-15 bius mac com #############################Solpot Crew Community############################## # # ReviewPost 2.5 (RP_PATH) Remote File Inclusion # # Donwload File : http://3-bius.com/ReviewPost.zip # ######################################################################## ######### # # # Bug Fou [ more ] [ reply ] |
|
Privacy Statement |
************************************************************************
*******
# Title : Techno Dreams FAQ Manager Package v1.0(faqview.asp) Remote SQL Injection Vulnerability
# Author : ajann
# Dork : faqview.asp?key
# Script Page : http://www.t-dreams.com
[ more ] [ reply ]