Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 06:33:58 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1688982048&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0910-exploits%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1688982048.1338186838.1338186838.1338186838.1%3B%2B__utmz%3D32867617.1338186838.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Packet Storm New Exploits For October, 2009 http://packetstormsecurity.org/files/82413/0910-exploits.tgz http://packetstormsecurity.org/files/82413/0910-exploits.tgz http://packetstormsecurity.org/files/82413/Packet-Storm-New-Exploits-For-October-2009.html Tue, 03 Nov 2009 04:04:25 GMT This archive contains all of the 209 exploits added to Packet Storm in October, 2009. PSArt 1.2 SQL Injection http://packetstormsecurity.org/files/82382/psart-sql.txt http://packetstormsecurity.org/files/82382/psart-sql.txt http://packetstormsecurity.org/files/82382/PSArt-1.2-SQL-Injection.html Fri, 30 Oct 2009 20:15:16 GMT PSArt version 1.2 suffers from a remote SQL injection vulnerability. Oracle Database AUTH_SESSKEY Exploit http://packetstormsecurity.org/files/82378/CVE-2009-1979.zip http://packetstormsecurity.org/files/82378/CVE-2009-1979.zip http://packetstormsecurity.org/files/82378/Oracle-Database-AUTH_SESSKEY-Exploit.html Fri, 30 Oct 2009 19:38:16 GMT Proof of concept exploit for Oracle Database versions 10.1.0.5 and 10.2.0.4 that relates to an improper AUTH_SESSKEY parameter length validation. CubeCart 4 Session Management Bypass http://packetstormsecurity.org/files/82377/cubecart4-bypass.txt http://packetstormsecurity.org/files/82377/cubecart4-bypass.txt http://packetstormsecurity.org/files/82377/CubeCart-4-Session-Management-Bypass.html Fri, 30 Oct 2009 19:37:01 GMT CubeCart 4 suffers from a really nasty session management bypass vulnerability. 2WIRE Remote Denial Of Service Proof Of Concept http://packetstormsecurity.org/files/82373/2os.py.txt http://packetstormsecurity.org/files/82373/2os.py.txt http://packetstormsecurity.org/files/82373/2WIRE-Remote-Denial-Of-Service-Proof-Of-Concept.html Fri, 30 Oct 2009 19:18:45 GMT Remote denial of service exploit for 2WIRE routers versions 5.29.52 and below. TikiWiki jhot Remote Command Execution http://packetstormsecurity.org/files/82371/tikiwiki_jhot_exec.rb.txt http://packetstormsecurity.org/files/82371/tikiwiki_jhot_exec.rb.txt http://packetstormsecurity.org/files/82371/TikiWiki-jhot-Remote-Command-Execution.html Fri, 30 Oct 2009 18:58:37 GMT TikiWiki contains a flaw that may allow a malicious user to execute arbitrary PHP code. The issue is triggered due to the jhot.php script not correctly verifying uploaded files. It is possible that the flaw may allow arbitrary PHP code execution by uploading a malicious PHP script resulting in a loss of integrity. The vulnerability has been reported in Tikiwiki version 1.9.4. TikiWiki tiki-graph_formula Remote Command Execution http://packetstormsecurity.org/files/82370/tikiwiki_graph_formula_exec.rb.txt http://packetstormsecurity.org/files/82370/tikiwiki_graph_formula_exec.rb.txt http://packetstormsecurity.org/files/82370/TikiWiki-tiki-graph_formula-Remote-Command-Execution.html Fri, 30 Oct 2009 18:57:02 GMT TikiWiki versions 1.9.8 and below contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'tiki-graph_formula.php' script not properly sanitizing user input supplied to the f variable, which may allow a remote attacker to execute arbitrary PHP commands resulting in a loss of integrity. SquirrelMail PGP Plugin Command Execution http://packetstormsecurity.org/files/82369/squirrelmail_pgp_plugin.rb.txt http://packetstormsecurity.org/files/82369/squirrelmail_pgp_plugin.rb.txt http://packetstormsecurity.org/files/82369/SquirrelMail-PGP-Plugin-Command-Execution.html Fri, 30 Oct 2009 18:55:07 GMT This Metasploit module exploits a command execution vulnerability in the PGP plugin of SquirrelMail. Simple PHP Blog 0.4.0 Command Execution http://packetstormsecurity.org/files/82368/sphpblog_file_upload.rb.txt http://packetstormsecurity.org/files/82368/sphpblog_file_upload.rb.txt http://packetstormsecurity.org/files/82368/Simple-PHP-Blog-0.4.0-Command-Execution.html Fri, 30 Oct 2009 18:53:25 GMT This Metasploit module combines three separate issues within The Simple PHP Blog (versions 0.4.0 and below) application to upload arbitrary data and thus execute a shell. The first vulnerability exposes the hash file (password.txt) to unauthenticated users. The second vulnerability lies within the image upload system provided to logged-in users; there is no image validation function in the blogger to prevent an authenticated user from uploading any file type. The third vulnerability occurs within the blog comment functionality, allowing arbitrary files to be deleted. phpBB viewtopic.php Arbitrary Code Execution http://packetstormsecurity.org/files/82367/phpbb_highlist.rb.txt http://packetstormsecurity.org/files/82367/phpbb_highlist.rb.txt http://packetstormsecurity.org/files/82367/phpBB-viewtopic.php-Arbitrary-Code-Execution.html Fri, 30 Oct 2009 18:51:38 GMT This Metasploit module exploits two arbitrary PHP code execution flaws in the phpBB forum system. The problem is that the 'highlight' parameter in the 'viewtopic.php' script is not verified properly and will allow an attacker to inject arbitrary code via preg_replace(). PHP XML-RPC Arbitrary Code Execution http://packetstormsecurity.org/files/82366/php_xmlrpc_eval.rb.txt http://packetstormsecurity.org/files/82366/php_xmlrpc_eval.rb.txt http://packetstormsecurity.org/files/82366/PHP-XML-RPC-Arbitrary-Code-Execution.html Fri, 30 Oct 2009 18:49:23 GMT This Metasploit module exploits an arbitrary code execution flaw discovered in many implementations of the PHP XML-RPC module. This flaw is exploitable through a number of PHP web applications, including but not limited to Drupal, Wordpress, Postnuke, and TikiWiki. WordPress cache_lastpostdate Arbitrary Code Execution http://packetstormsecurity.org/files/82365/php_wordpress_lastpost.rb.txt http://packetstormsecurity.org/files/82365/php_wordpress_lastpost.rb.txt http://packetstormsecurity.org/files/82365/WordPress-cache_lastpostdate-Arbitrary-Code-Execution.html Fri, 30 Oct 2009 18:47:48 GMT This Metasploit module exploits an arbitrary PHP code execution flaw in the WordPress blogging software. This vulnerability is only present when the PHP 'register_globals' option is enabled (common for hosting providers). All versions of WordPress prior to 1.5.1.3 are affected. vBulletin misc.php Template Name Arbitrary Code Execution http://packetstormsecurity.org/files/82364/php_vbulletin_template.rb.txt http://packetstormsecurity.org/files/82364/php_vbulletin_template.rb.txt http://packetstormsecurity.org/files/82364/vBulletin-misc.php-Template-Name-Arbitrary-Code-Execution.html Fri, 30 Oct 2009 18:45:56 GMT This Metasploit module exploits an arbitrary PHP code execution flaw in the vBulletin web forum software. This vulnerability is only present when the "Add Template Name in HTML Comments" option is enabled. All versions of vBulletin prior to 3.0.7 are affected. PAJAX Remote Command Execution http://packetstormsecurity.org/files/82363/pajax_remote_exec.rb.txt http://packetstormsecurity.org/files/82363/pajax_remote_exec.rb.txt http://packetstormsecurity.org/files/82363/PAJAX-Remote-Command-Execution.html Fri, 30 Oct 2009 18:40:19 GMT RedTeam has identified two security flaws in PAJAX versions 0.5.1 and below. It is possible to execute arbitrary PHP code from unchecked user input. Additionally, it is possible to include arbitrary files on the server ending in ".class.php". HP Openview connectedNodes.ovpl Remote Command Execution http://packetstormsecurity.org/files/82362/openview_connectednodes_exec.rb.txt http://packetstormsecurity.org/files/82362/openview_connectednodes_exec.rb.txt http://packetstormsecurity.org/files/82362/HP-Openview-connectedNodes.ovpl-Remote-Command-Execution.html Fri, 30 Oct 2009 18:36:15 GMT This Metasploit module exploits an arbitrary command execution vulnerability in the HP OpenView connectedNodes.ovpl CGI application. The results of the command will be displayed to the screen. Nagios3 statuswml.cgi Ping Command Execution http://packetstormsecurity.org/files/82361/nagios3_statuswml_ping.rb.txt http://packetstormsecurity.org/files/82361/nagios3_statuswml_ping.rb.txt http://packetstormsecurity.org/files/82361/Nagios3-statuswml.cgi-Ping-Command-Execution.html Fri, 30 Oct 2009 18:33:33 GMT This Metasploit module abuses a metacharacter injection vulnerability in the Nagios3 statuswml.cgi script. This flaw is triggered when shell metacharacters are present in the parameters to the ping and traceroute commands. Mambo Cache_Lite Class mosConfig_absolute_path Remote File Inclusion http://packetstormsecurity.org/files/82360/mambo_cache_lite.rb.txt http://packetstormsecurity.org/files/82360/mambo_cache_lite.rb.txt http://packetstormsecurity.org/files/82360/Mambo-Cache_Lite-Class-mosConfig_absolute_path-Remote-File-Inclusion.html Fri, 30 Oct 2009 18:31:46 GMT This Metasploit module exploits a remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier. Matt Wright guestbook.pl Arbitrary Command Execution http://packetstormsecurity.org/files/82359/guestbook_ssi_exec.rb.txt http://packetstormsecurity.org/files/82359/guestbook_ssi_exec.rb.txt http://packetstormsecurity.org/files/82359/Matt-Wright-guestbook.pl-Arbitrary-Command-Execution.html Fri, 30 Oct 2009 18:12:30 GMT The Matt Wright guestbook.pl versions 2.3.1 and below CGI script contains a flaw that may allow arbitrary command execution. The vulnerability requires that HTML posting is enabled in the guestbook.pl script, and that the web server must have the Server-Side Include (SSI) script handler enabled for the '.html' file type. By combining the script weakness with non-default server configuration, it is possible to exploit this vulnerability successfully. Joomla 1.5.12 TinyBrowser File Upload Code Execution http://packetstormsecurity.org/files/82358/joomla_tinybrowser.rb.txt http://packetstormsecurity.org/files/82358/joomla_tinybrowser.rb.txt http://packetstormsecurity.org/files/82358/Joomla-1.5.12-TinyBrowser-File-Upload-Code-Execution.html Fri, 30 Oct 2009 18:10:22 GMT This Metasploit module exploits a vulnerability in the TinyMCE/tinybrowser plugin. This plugin is not secured in version 1.5.12 of joomla and allows the upload of files on the remote server. By renaming the uploaded file this vulnerability can be used to upload/execute code on the affected system. Google Appliance ProxyStyleSheet Command Execution http://packetstormsecurity.org/files/82357/google_proxystylesheet_exec.rb.txt http://packetstormsecurity.org/files/82357/google_proxystylesheet_exec.rb.txt http://packetstormsecurity.org/files/82357/Google-Appliance-ProxyStyleSheet-Command-Execution.html Fri, 30 Oct 2009 18:08:54 GMT This Metasploit module exploits a feature in the Saxon XSLT parser used by the Google Search Appliance. This feature allows for arbitrary java methods to be called. Google released a patch and advisory to their client base in August of 2005 (GA-2005-08-m). The target appliance must be able to connect back to your machine for this exploit to work. Dogfood CRM spell.php Remote Command Execution http://packetstormsecurity.org/files/82356/dogfood_spell_exec.rb.txt http://packetstormsecurity.org/files/82356/dogfood_spell_exec.rb.txt http://packetstormsecurity.org/files/82356/Dogfood-CRM-spell.php-Remote-Command-Execution.html Fri, 30 Oct 2009 18:06:37 GMT This Metasploit module exploits a previously unpublished vulnerability in the Dogfood CRM mail function which is vulnerable to command injection in the spell check feature. Because of character restrictions, this exploit works best with the double-reverse telnet payload. This vulnerability was discovered by LSO and affects version 2.0.10. Cacti graph_view.php Remote Command Execution http://packetstormsecurity.org/files/82355/cacti_graphimage_exec.rb.txt http://packetstormsecurity.org/files/82355/cacti_graphimage_exec.rb.txt http://packetstormsecurity.org/files/82355/Cacti-graph_view.php-Remote-Command-Execution.html Fri, 30 Oct 2009 18:03:33 GMT This Metasploit module exploits an arbitrary command execution vulnerability in the Raxnet Cacti 'graph_view.php' script. All versions of Raxnet Cacti prior to 0.8.6-d are vulnerable. BASE base_qry_common Remote File Include http://packetstormsecurity.org/files/82354/base_qry_common.rb.txt http://packetstormsecurity.org/files/82354/base_qry_common.rb.txt http://packetstormsecurity.org/files/82354/BASE-base_qry_common-Remote-File-Include.html Fri, 30 Oct 2009 18:02:08 GMT This Metasploit module exploits a remote file inclusion vulnerability in the base_qry_common.php file in BASE 1.2.4 and earlier. Barracuda IMG.PL Remote Command Execution http://packetstormsecurity.org/files/82353/barracuda_img_exec.rb.txt http://packetstormsecurity.org/files/82353/barracuda_img_exec.rb.txt http://packetstormsecurity.org/files/82353/Barracuda-IMG.PL-Remote-Command-Execution.html Fri, 30 Oct 2009 18:00:12 GMT This Metasploit module exploits an arbitrary command execution vulnerability in the Barracuda Spam Firewall appliance. Versions prior to 3.1.18 are vulnerable. AWStats migrate Remote Command Execution http://packetstormsecurity.org/files/82352/awstats_migrate_exec.rb.txt http://packetstormsecurity.org/files/82352/awstats_migrate_exec.rb.txt http://packetstormsecurity.org/files/82352/AWStats-migrate-Remote-Command-Execution.html Fri, 30 Oct 2009 17:58:36 GMT This Metasploit module exploits an arbitrary command execution vulnerability in the AWStats CGI script. AWStats v6.4 and v6.5 are vulnerable. Perl based payloads are recommended with this module. The vulnerability is only present when AllowToUpdateStatsFromBrowser is enabled in the AWstats configuration file (non-default).