网络安全
-
AuraCMS
#!/usr/bin/perl# k1tk4t Public Security Advisory# ////////////////////////////////////////////////////////////# AuraCMS <= 2.2.2 (pages_data.php) Arbitrary Edit/Add/Delete data halaman exploit # Vendor : http://www.auracms.org/...
-
minb 0.1.0 Remote Code Execution Exploit
#!/usr/bin/python######################################################################################### minb Remote Code Execution Exploit #######################################################...
-
Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln
------------------------------------------------------------------------------------------- Joomla Component com_content SQL Injection Vulnerabity ------------------...
-
Adobe Acrobat 9 ActiveX Remote Denial of Service Exploit
<!-- Jeremy Brown (0xjbrown41@gmail.com/jbrownsec.blogspot.com) Adobe Acrobat 9 Remote DoS (--) Tested on AA9/IE7/Vista I can't seem to reproduce this on XP! Oh well. Of course the most popular app for reading pdfs is SfS/S...
-
Mole Group Last Minute Script
-[*] ================================================================================ [*]--[*] Last Minute Script <= 4.0 Remote SQL Injection Vulnerability [*]--[*] =============================================================...
-
Wordpress 2.6.1 (SQL Column Truncation) Admin Takeover Exploit
#!/usr/bin/php<?php# ------------------------------------------------------------# quick'n'dirty wordpress admin-take0ver poc# by iso^kpsbr in august 2oo8 ## works w/ wordpress 2.6.1## .oO( private -- do not...
-
BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit
#!/usr/bin/perl#=================================================# BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit#=================================================## ,--^----------,--------,-----,-------^--,# | ||||||||| `-----...
-
Boonex Dolphin 6.1.2 Multiple Remote File Inclusion Vulnerabilities
# Name Of Script : Dolphin PHP# Version : 6.1.2# Download From : http://heanet.dl.sourceforge.net/sourceforge/boonex-dolphin/Dolphin-v.6.1.2-Free.zip# Found By : RoMaNcYxHaCkEr [ RoMaNTiC-TeaM ]# My Home Page : WwW.4RxH.CoM [...
-
Poppler
############################################################################## Felipe Andres Manzano * fmanzano@fceia.unr.edu.ar ######## updates in http://felipe.andres.manzano.googlepages.com/home ####################...
-
Download Accelerator Plus - DAP 8.x m3u File Buffer Overflow Exploit (c)
#include <stdio.h>#include <stdlib.h>/*DAP 8.x (.m3u) File BOF C Exploit for XP SP2,SP3 EnglishSecurityFocus Advisory:Download Accelerator Plus (DAP) is prone to a buffer-overflow vulnerability because it fails...
-
trixbox (langChoice) Local File Inclusion Exploit (connect-back)
#!/usr/bin/perl -w# Jean-Michel BESNARD - LEXSI Audit# 2008-07-08# perl trixbox_fi.pl 192.168.1.212# Please listen carefully as our menu option has changed# Choose from the following options:# 1> Remote TCP shell#...
-
OllyDBG v1.10 and ImpREC v1.7f (export name) BOF PoC
;-------------------------------------------------------------------------;; OllyDBG v1.10 and ImpREC v1.7f export name buffer overflow vulnerability; PoC (probably older versions affected too, not tested though.) ;; Included...
-
Mole Group Real Estate Script
-[*] ================================================================================ [*]--[*] Real Estate Script <= 1.1 Remote SQL Injection Vulnerability [*]--[*] ==============================================================...
-
Download Accelerator Plus - DAP 8.x (m3u) Local BOF Exploit 0day
#!/usr/bin/python# Download Accelerator Plus - DAP 8.x (m3u) 0day Local Buffer Overflow Exploit# Bug discovered by Krystian Kloskowski (h07) <h07@interia.pl># Tested on: Download Accelerator Plus 8.6 / XP SP2 Polish# Shellcode:...
-
tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities
################################################################################### Viva IslaM Viva IslaM ######################## Remote SQL injection Vulnerability#### tplSoccerSite 1.0 ( player.php id )##...
-
Safari Quicktime
#!/usr/bin/perl## quickbite.pl## Safari Quicktime <= 7.3 RTSP Content-Type overflow exploit# for Mac OS X (Intel)## Tested with OS X 10.4.# On victim, browse to http://server:8080/# Binds shell on port 4444....
-
WebCMS Portal Edition (id) Remote SQL Injection Vulnerability
################################################################################### Viva IslaM Viva IslaM ######################## Remote SQL InjEcti0n Vulnerability#### WebCMS Portal ( index.php menu )##...
-
PHP 4.4.5 / 4.4.6 session_decode() Double Free Exploit PoC
<?php //////////////////////////////////////////////////////////////////////// // _ _ _ _ ___ _ _ ___ // // | || | __ _ _ _ __| | ___ _ _ ___ __| | ___ | _ | || || _ //...
-
Microsoft DNS Server (Dynamic DNS Updates) Remote Exploit
/* Exploiting Microsoft DNS Dynamic Updates for Fun and profit Andres Tarasco Acu?a - (c) 2007 Url: http://www.514.es By default, most Microsoft DNS servers integrated with active directory allow insecure dynamic updates f...
-
Pragyan CMS 2.6.2 (sourceFolder) Remote File Inclusion Vulnerability
<< In The Name Of GOD >> ------------------------------------------------------------- - [ Persian Boys Hacking Team ] -:- 2008 -...
-
fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (php)
#!/usr/bin/php<?php#### Fuzzylime 3.01 Remote Code Execution## Credits: Inphex and real#### [C:]# php fuzzylime.php http://www.target.com/fuzzylime/## [target][cmd]# id## uid=63676(dswrealty) gid=888(vusers) groups=...
-
Maian Uploader
-[*] ================================================================================ [*]--[*] Maian Uploader <= v4.0 Insecure Cookie Handling Vulnerability [*]--[*] ======================================================...
-
Galatolo Web Manager 1.3a
--== ============================================================================ ==----== Galatolo Web Manager 1.3a <= XSS / Remote SQL Injection Vulnerability ==-- --== ==========================================================...
-
FreeBSD mcweject 0.9 (eject) Local Root Buffer Overflow Exploit
// ejecsploit.c - local root exploit for bsd's eject.c // harry // vuln found by kokanin (you 31337!!! ;)) // thanks to sacrine and all the other netric guys!!! you rule :) #include <stdio.h> #include <stdlib.h>...
