Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 05:32:56 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1768766752&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0702-exploits%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1768766752.1338183176.1338183176.1338183176.1%3B%2B__utmz%3D32867617.1338183176.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) 0702-exploits.tgz http://packetstormsecurity.org/files/54818/0702-exploits.tgz http://packetstormsecurity.org/files/54818/0702-exploits.tgz http://packetstormsecurity.org/files/54818/0702-exploits.tgz.html Tue, 06 Mar 2007 05:08:23 GMT Packet Storm new exploits for February, 2007. Netragard Security Advisory 2007-02-20 http://packetstormsecurity.org/files/54808/NETRAGARD-20070220-1.txt http://packetstormsecurity.org/files/54808/NETRAGARD-20070220-1.txt http://packetstormsecurity.org/files/54808/Netragard-Security-Advisory-2007-02-20.html Tue, 06 Mar 2007 04:20:27 GMT Netragard, L.L.C Advisory - McAfee Virex contains an exploitable feature that enables users to define what files should be excluded for scanning. This feature relies on a configuration file with insecure privileges and is located in /Library/Application Support. Any user on the system can modify or delete the configuration file thus affecting what Virex will scan. Versions 7.7 and below are affected. kiwicat-exec.txt http://packetstormsecurity.org/files/54807/kiwicat-exec.txt http://packetstormsecurity.org/files/54807/kiwicat-exec.txt http://packetstormsecurity.org/files/54807/kiwicat-exec.txt.html Tue, 06 Mar 2007 04:17:28 GMT Kiwi CatTools TFTP versions up to 3.2.8 suffer from information disclosure and remote code execution flaws. shoutcast-xss.txt http://packetstormsecurity.org/files/54805/shoutcast-xss.txt http://packetstormsecurity.org/files/54805/shoutcast-xss.txt http://packetstormsecurity.org/files/54805/shoutcast-xss.txt.html Tue, 06 Mar 2007 04:14:07 GMT Nullsoft ShoutcastServer version 1.9.7/Win32 suffers from a cross site scripting flaw. scip-2962.txt http://packetstormsecurity.org/files/54803/scip-2962.txt http://packetstormsecurity.org/files/54803/scip-2962.txt http://packetstormsecurity.org/files/54803/scip-2962.txt.html Tue, 06 Mar 2007 04:10:21 GMT Wordpress version 2.1.1 suffers from multiple script injection vulnerabilities. SA-20070226-0.txt http://packetstormsecurity.org/files/54791/SA-20070226-0.txt http://packetstormsecurity.org/files/54791/SA-20070226-0.txt http://packetstormsecurity.org/files/54791/SA-20070226-0.txt.html Tue, 06 Mar 2007 00:51:48 GMT SEC Consult Security Advisory 20070226-0 - The 3rd party module Pagesetter for PostNuke is susceptible to a local file inclusion vulnerability. Versions 6.2.0 and 6.3.0 beta 5 are affected. unorg-sql.txt http://packetstormsecurity.org/files/54723/unorg-sql.txt http://packetstormsecurity.org/files/54723/unorg-sql.txt http://packetstormsecurity.org/files/54723/unorg-sql.txt.html Wed, 28 Feb 2007 00:53:18 GMT It appears that the un.org web site suffers from SQL injection vulnerabilities. sqllitemanager120-multi.txt http://packetstormsecurity.org/files/54719/sqllitemanager120-multi.txt http://packetstormsecurity.org/files/54719/sqllitemanager120-multi.txt http://packetstormsecurity.org/files/54719/sqllitemanager120-multi.txt.html Wed, 28 Feb 2007 00:47:52 GMT SQLiteManager version 1.2.0 suffers from local file inclusion and multiple cross site scripting vulnerabilities. coppermine-blindsql.txt http://packetstormsecurity.org/files/54717/coppermine-blindsql.txt http://packetstormsecurity.org/files/54717/coppermine-blindsql.txt http://packetstormsecurity.org/files/54717/coppermine-blindsql.txt.html Wed, 28 Feb 2007 00:45:24 GMT Coppermine Photo Gallery version 1.3.x blind SQL injection exploit. photostand120-xss.txt http://packetstormsecurity.org/files/54716/photostand120-xss.txt http://packetstormsecurity.org/files/54716/photostand120-xss.txt http://packetstormsecurity.org/files/54716/photostand120-xss.txt.html Wed, 28 Feb 2007 00:43:23 GMT Photostand version 1.2.0 suffers from multiple cross site scripting vulnerabilities. activecal120-multi.txt http://packetstormsecurity.org/files/54715/activecal120-multi.txt http://packetstormsecurity.org/files/54715/activecal120-multi.txt http://packetstormsecurity.org/files/54715/activecal120-multi.txt.html Wed, 28 Feb 2007 00:38:41 GMT ActiveCalendar version 1.2.0 suffers from cross site scripting and local file inclusion vulnerabilities. pickle-lfi.txt http://packetstormsecurity.org/files/54714/pickle-lfi.txt http://packetstormsecurity.org/files/54714/pickle-lfi.txt http://packetstormsecurity.org/files/54714/pickle-lfi.txt.html Wed, 28 Feb 2007 00:37:40 GMT Pickle suffers from a local file download vulnerability. sof-multi.txt http://packetstormsecurity.org/files/54712/sof-multi.txt http://packetstormsecurity.org/files/54712/sof-multi.txt http://packetstormsecurity.org/files/54712/sof-multi.txt.html Wed, 28 Feb 2007 00:35:00 GMT Simple One-File Gallery suffers from local file inclusion and cross site scripting vulnerabilities. sitex-multi.txt http://packetstormsecurity.org/files/54711/sitex-multi.txt http://packetstormsecurity.org/files/54711/sitex-multi.txt http://packetstormsecurity.org/files/54711/sitex-multi.txt.html Wed, 28 Feb 2007 00:33:36 GMT sitex suffers from upload and cross site scripting vulnerabilities. xtcommerce-lfi.txt http://packetstormsecurity.org/files/54667/xtcommerce-lfi.txt http://packetstormsecurity.org/files/54667/xtcommerce-lfi.txt http://packetstormsecurity.org/files/54667/xtcommerce-lfi.txt.html Sat, 24 Feb 2007 03:06:11 GMT xtcommerce suffers from a local file inclusion vulnerability. shopkitplus-lfi.txt http://packetstormsecurity.org/files/54665/shopkitplus-lfi.txt http://packetstormsecurity.org/files/54665/shopkitplus-lfi.txt http://packetstormsecurity.org/files/54665/shopkitplus-lfi.txt.html Sat, 24 Feb 2007 03:03:57 GMT shopkitplus suffers from a local file inclusion vulnerability. zpanel.txt http://packetstormsecurity.org/files/54658/zpanel.txt http://packetstormsecurity.org/files/54658/zpanel.txt http://packetstormsecurity.org/files/54658/zpanel.txt.html Sat, 24 Feb 2007 02:55:51 GMT ZPanel suffers from a remote file inclusion vulnerability. spydir.c http://packetstormsecurity.org/files/54653/spydir.c http://packetstormsecurity.org/files/54653/spydir.c http://packetstormsecurity.org/files/54653/spydir.c.html Sat, 24 Feb 2007 02:47:11 GMT Exploit that demonstrates the vulnerability in ReadDirectoryChangesW() for Microsoft Windows 2000/XP/2003/Vista. webspell40-multi.txt http://packetstormsecurity.org/files/54651/webspell40-multi.txt http://packetstormsecurity.org/files/54651/webspell40-multi.txt http://packetstormsecurity.org/files/54651/webspell40-multi.txt.html Sat, 24 Feb 2007 02:33:14 GMT WebSpell versions greater than 4.0 suffer from authentication bypass and arbitrary code execution flaws. saphplesson30-sql.txt http://packetstormsecurity.org/files/54650/saphplesson30-sql.txt http://packetstormsecurity.org/files/54650/saphplesson30-sql.txt http://packetstormsecurity.org/files/54650/saphplesson30-sql.txt.html Sat, 24 Feb 2007 02:28:10 GMT SaphpLesson version 3.0 suffers from a remote SQL injection vulnerability. pheap.txt http://packetstormsecurity.org/files/54648/pheap.txt http://packetstormsecurity.org/files/54648/pheap.txt http://packetstormsecurity.org/files/54648/pheap.txt.html Sat, 24 Feb 2007 02:25:25 GMT Pheap CMS suffers from a local file inclusion vulnerability that allows for the editing of the file. lovecms14-multi.txt http://packetstormsecurity.org/files/54647/lovecms14-multi.txt http://packetstormsecurity.org/files/54647/lovecms14-multi.txt http://packetstormsecurity.org/files/54647/lovecms14-multi.txt.html Sat, 24 Feb 2007 02:24:14 GMT LoveCMS version 1.4 suffers from remote file inclusion, local file inclusion, upload, and cross site scripting vulnerabilities. plantilla.txt http://packetstormsecurity.org/files/54646/plantilla.txt http://packetstormsecurity.org/files/54646/plantilla.txt http://packetstormsecurity.org/files/54646/plantilla.txt.html Sat, 24 Feb 2007 02:23:24 GMT Plantilla PHP suffers from local file inclusion and arbitrary file upload vulnerabilities. jbrowser.txt http://packetstormsecurity.org/files/54644/jbrowser.txt http://packetstormsecurity.org/files/54644/jbrowser.txt http://packetstormsecurity.org/files/54644/jbrowser.txt.html Sat, 24 Feb 2007 02:21:44 GMT It appears that JBrowser may allow arbitrary access to admin/config files. oraclekupv-perm.txt http://packetstormsecurity.org/files/54643/oraclekupv-perm.txt http://packetstormsecurity.org/files/54643/oraclekupv-perm.txt http://packetstormsecurity.org/files/54643/oraclekupv-perm.txt.html Sat, 24 Feb 2007 02:20:18 GMT Oracle 10g KUPW$WORKER.MAIN Grant/Revoke dba permission exploit.