<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
  <title>Files &#8776; Packet Storm</title>
  <description>Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers</description>
  <link>http://packetstormsecurity.org/</link>
  <language>en-us</language>
  <lastBuildDate>Wed, 23 May 2012 12:56:21 GMT</lastBuildDate>

  <image>
    <title>Packet Storm</title>
    <width>144</width><height>400</height>
    <link>http://packetstormsecurity.org/</link>
    <url>http://www.google-analytics.com/__utm.gif?utmwv=1.3&amp;utmn=1527293096&amp;utmcs=ISO-8859-1&amp;utmsr=31337x31337&amp;utmsc=32-bit&amp;utmul=en-us&amp;utmje=0&amp;utmfl=-&amp;utmcn=1&amp;utmdt=Files%u2248%20Packet%20Storm&amp;utmhn=packetstormsecurity.org&amp;utmr=-&amp;utmp=%2Ffiles%2F&amp;utmac=UA-18885198-1&amp;utmcc=__utma%3D32867617.1527293096.1337777781.1337777781.1337777781.1%3B%2B__utmz%3D32867617.1337777781.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none)</url>
  </image>
 
<item>
<title>Ajaxmint Gallery 1.0 Local File Inclusion</title>
<link>http://packetstormsecurity.org/files/112970/ajamintgallery-lfi.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112970/ajamintgallery-lfi.txt</guid>
<comments>http://packetstormsecurity.org/files/112970/Ajaxmint-Gallery-1.0-Local-File-Inclusion.html</comments>
<pubDate>Wed, 23 May 2012 02:52:42 GMT</pubDate>
<description>Ajaxmint Gallery version 1.0 suffers from a local file inclusion vulnerability.</description>
<category></category>
</item>
<item>
<title>RuubikCMS 1.1.0 Beta XSS / Disclosure / Directory Traversal</title>
<link>http://packetstormsecurity.org/files/112969/ruubik111-xssdisclosetraversal.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112969/ruubik111-xssdisclosetraversal.txt</guid>
<comments>http://packetstormsecurity.org/files/112969/RuubikCMS-1.1.0-Beta-XSS-Disclosure-Directory-Traversal.html</comments>
<pubDate>Wed, 23 May 2012 02:50:41 GMT</pubDate>
<description>RuubikCMS version 1.1.0 Beta suffers from cross site scripting, information disclosure, and directory traversal vulnerabilities.</description>
<category></category>
</item>
<item>
<title>Novell Client 4.91 SP3/4 Privilege Escalation </title>
<link>http://packetstormsecurity.org/files/112968/novell491-escalate.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112968/novell491-escalate.txt</guid>
<comments>http://packetstormsecurity.org/files/112968/Novell-Client-4.91-SP3-4-Privilege-Escalation.html</comments>
<pubDate>Wed, 23 May 2012 02:49:43 GMT</pubDate>
<description>Novell Client version 4.91 SP3/4 privilege escalation exploit for Win2K3 and WinXP.</description>
<category></category>
</item>
<item>
<title>Windows XP Keyboard Layouts Pool Corruption Proof Of Concept</title>
<link>http://packetstormsecurity.org/files/112967/winxpkeyboard.zip</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112967/winxpkeyboard.zip</guid>
<comments>http://packetstormsecurity.org/files/112967/Windows-XP-Keyboard-Layouts-Pool-Corruption-Proof-Of-Concept.html</comments>
<pubDate>Wed, 23 May 2012 02:45:29 GMT</pubDate>
<description>This proof of concept code demonstrates a Microsoft Windows XP keyboard layouts pool corruption vulnerability, post MS12-034. The vulnerability exists in the function win32k!ReadLayoutFile() that parses keyboard layout file data.</description>
<category></category>
</item>
<item>
<title>Supernews 2.6.1 SQL Injection</title>
<link>http://packetstormsecurity.org/files/112966/supernews261-sql.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112966/supernews261-sql.txt</guid>
<comments>http://packetstormsecurity.org/files/112966/Supernews-2.6.1-SQL-Injection.html</comments>
<pubDate>Wed, 23 May 2012 02:44:00 GMT</pubDate>
<description>Supernews versions 2.6.1 and below remote SQL injection exploit.</description>
<category></category>
</item>
<item>
<title>Failure To Restrict Access</title>
<link>http://packetstormsecurity.org/files/112965/Failure_to_restrict_access_tool.pdf</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112965/Failure_to_restrict_access_tool.pdf</guid>
<comments>http://packetstormsecurity.org/files/112965/Failure-To-Restrict-Access.html</comments>
<pubDate>Wed, 23 May 2012 02:33:16 GMT</pubDate>
<description>This is a brief whitepaper discussing methods of validating a lack of access restriction for various pages on sites. It discusses everything from visual viewing and comparison between cookies used and using an implementation of the Damerau-Levensthein model. They also have a tool for download.</description>
<category></category>
</item>
<item>
<title>PHPCollab 2.5 Database Backup Disclosure</title>
<link>http://packetstormsecurity.org/files/112964/phpcollab-disclose.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112964/phpcollab-disclose.txt</guid>
<comments>http://packetstormsecurity.org/files/112964/PHPCollab-2.5-Database-Backup-Disclosure.html</comments>
<pubDate>Wed, 23 May 2012 02:29:01 GMT</pubDate>
<description>PHPCollab version 2.5 suffers from an unauthenticated database backup download vulnerability.</description>
<category></category>
</item>
<item>
<title>Tftpd32 DHCP Serve 4.00 Denial Of Service</title>
<link>http://packetstormsecurity.org/files/112963/tftpd32-dos.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112963/tftpd32-dos.txt</guid>
<comments>http://packetstormsecurity.org/files/112963/Tftpd32-DHCP-Serve-4.00-Denial-Of-Service.html</comments>
<pubDate>Wed, 23 May 2012 02:27:39 GMT</pubDate>
<description>Tftpd32 DHCP server version 4.00 suffers from a denial of service vulnerability.</description>
<category></category>
</item>
<item>
<title>Ubuntu Security Notice USN-1449-1</title>
<link>http://packetstormsecurity.org/files/112956/USN-1449-1.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112956/USN-1449-1.txt</guid>
<comments>http://packetstormsecurity.org/files/112956/Ubuntu-Security-Notice-USN-1449-1.html</comments>
<pubDate>Tue, 22 May 2012 20:37:23 GMT</pubDate>
<description>Ubuntu Security Notice 1449-1 - It was discovered that feedparser did not properly sanitize ENTITY declarations in encoded fields. A remote attacker could exploit this to cause a denial of service via memory exhaustion.</description>
<category></category>
</item>
<item>
<title>PHP CGI Argument Injection</title>
<link>http://packetstormsecurity.org/files/112971/phpcgi-exploit.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112971/phpcgi-exploit.txt</guid>
<comments>http://packetstormsecurity.org/files/112971/PHP-CGI-Argument-Injection.html</comments>
<pubDate>Tue, 22 May 2012 11:11:11 GMT</pubDate>
<description>PHP CGI argument injection remote exploit version 0.3. Works on versions up to 5.3.12 and 5.4.2.</description>
<category></category>
</item>
<item>
<title>Nmap Port Scanner 6.00</title>
<link>http://packetstormsecurity.org/files/112951/nmap-6.00.tgz</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112951/nmap-6.00.tgz</guid>
<comments>http://packetstormsecurity.org/files/112951/Nmap-Port-Scanner-6.00.html</comments>
<pubDate>Tue, 22 May 2012 04:00:28 GMT</pubDate>
<description>Nmap is a utility for port scanning large networks, although it works fine for single hosts. Sometimes you need speed, other times you may need stealth. In some cases, bypassing firewalls may be required. Not to mention the fact that you may want to scan different protocols (UDP, TCP, ICMP, etc.). Nmap supports Vanilla TCP connect() scanning, TCP SYN (half open) scanning, TCP FIN, Xmas, or NULL (stealth) scanning, TCP ftp proxy (bounce attack) scanning, SYN/FIN scanning using IP fragments (bypasses some packet filters), TCP ACK and Window scanning, UDP raw ICMP port unreachable scanning, ICMP scanning (ping-sweep), TCP Ping scanning, Direct (non portmapper) RPC scanning, Remote OS Identification by TCP/IP Fingerprinting, and Reverse-ident scanning. Nmap also supports a number of performance and reliability features such as dynamic delay time calculations, packet timeout and retransmission, parallel port scanning, detection of down hosts via parallel pings.</description>
<category></category>
</item>
<item>
<title>Mandriva Linux Security Advisory 2012-079</title>
<link>http://packetstormsecurity.org/files/112950/MDVSA-2012-079.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112950/MDVSA-2012-079.txt</guid>
<comments>http://packetstormsecurity.org/files/112950/Mandriva-Linux-Security-Advisory-2012-079.html</comments>
<pubDate>Tue, 22 May 2012 03:54:01 GMT</pubDate>
<description>Mandriva Linux Security Advisory 2012-079 - A flaw exists in the IP network matching code in sudo versions 1.6.9p3 through 1.8.4p4 that may result in the local host being matched even though it is not actually part of the network described by the IP address and associated netmask listed in the sudoers file or in LDAP. As a result, users authorized to run commands on certain IP networks may be able to run commands on hosts that belong to other networks not explicitly listed in sudoers. The updated packages have been patched to correct this issue.</description>
<category></category>
</item>
<item>
<title>Yandex.Server 2010 9.0 Enterprise Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/112945/yandex-xss.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112945/yandex-xss.txt</guid>
<comments>http://packetstormsecurity.org/files/112945/Yandex.Server-2010-9.0-Enterprise-Cross-Site-Scripting.html</comments>
<pubDate>Tue, 22 May 2012 03:38:00 GMT</pubDate>
<description>Yandex.Server version 2010 9.0 Enterprise suffers from a cross site scripting vulnerability.</description>
<category></category>
</item>
<item>
<title>FlexNet License Server Manager lmgrd Buffer Overflow</title>
<link>http://packetstormsecurity.org/files/112919/flexnet_lmgrd_bof.rb.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112919/flexnet_lmgrd_bof.rb.txt</guid>
<comments>http://packetstormsecurity.org/files/112919/FlexNet-License-Server-Manager-lmgrd-Buffer-Overflow.html</comments>
<pubDate>Tue, 22 May 2012 01:40:17 GMT</pubDate>
<description>This Metasploit module exploits a vulnerability in the FlexNet License Server Manager. The vulnerability is due to the insecure usage of memcpy in the lmgrd service when handling network packets, which results in a stack buffer overflow. In order to improve reliability, this module will make lots of connections to lmgrd during each attempt to maximize its success.</description>
<category></category>
</item>
<item>
<title>Foxit Reader 3.0 Open Execute Action Stack Based Buffer Overflow</title>
<link>http://packetstormsecurity.org/files/112918/foxit_reader_launch.rb.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112918/foxit_reader_launch.rb.txt</guid>
<comments>http://packetstormsecurity.org/files/112918/Foxit-Reader-3.0-Open-Execute-Action-Stack-Based-Buffer-Overflow.html</comments>
<pubDate>Tue, 22 May 2012 01:39:05 GMT</pubDate>
<description>This Metasploit module exploits a buffer overflow in Foxit Reader 3.0 builds 1301 and earlier. Due to the way Foxit Reader handles the input from an &quot;Launch&quot; action, it is possible to cause a stack-based buffer overflow, allowing an attacker to gain arbitrary code execution under the context of the user.</description>
<category></category>
</item>
<item>
<title>HP StorageWorks P4000 Virtual SAN Appliance Command Execution</title>
<link>http://packetstormsecurity.org/files/112917/hp_vsa_exec.rb.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112917/hp_vsa_exec.rb.txt</guid>
<comments>http://packetstormsecurity.org/files/112917/HP-StorageWorks-P4000-Virtual-SAN-Appliance-Command-Execution.html</comments>
<pubDate>Tue, 22 May 2012 01:38:49 GMT</pubDate>
<description>This Metasploit module exploits a vulnerability found in HP&#39;s StorageWorks P4000 VSA on versions prior to 9.5. By using a default account credential, it is possible to inject arbitrary commands as part of a ping request via port 13838.</description>
<category></category>
</item>
<item>
<title>Active Collab &quot;chat module&quot; 2.3.8 Remote PHP Code Injection </title>
<link>http://packetstormsecurity.org/files/112916/activecollab_chat.rb.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112916/activecollab_chat.rb.txt</guid>
<comments>http://packetstormsecurity.org/files/112916/Active-Collab-chat-module-2.3.8-Remote-PHP-Code-Injection.html</comments>
<pubDate>Tue, 22 May 2012 01:37:25 GMT</pubDate>
<description>This Metasploit module exploits an arbitrary code injection vulnerability in the chat module that is part of Active Collab by abusing a preg_replace() using the /e modifier and its replacement string using double quotes. The vulnerable function can be found in activecollab/application/modules/chat/functions/html_to_text.php.</description>
<category></category>
</item>
<item>
<title>Debian Security Advisory 2476-1</title>
<link>http://packetstormsecurity.org/files/112912/dsa-2476-1.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112912/dsa-2476-1.txt</guid>
<comments>http://packetstormsecurity.org/files/112912/Debian-Security-Advisory-2476-1.html</comments>
<pubDate>Tue, 22 May 2012 00:25:44 GMT</pubDate>
<description>Debian Linux Security Advisory 2476-1 - intrigeri discovered a format string error in pidgin-otr, an off-the-record messaging plugin for Pidgin.</description>
<category></category>
</item>
<item>
<title>Ubuntu Security Notice USN-1448-1</title>
<link>http://packetstormsecurity.org/files/112911/USN-1448-1.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112911/USN-1448-1.txt</guid>
<comments>http://packetstormsecurity.org/files/112911/Ubuntu-Security-Notice-USN-1448-1.html</comments>
<pubDate>Tue, 22 May 2012 00:25:24 GMT</pubDate>
<description>Ubuntu Security Notice 1448-1 - A flaw was found in the Linux kernel&#39;s KVM (Kernel Virtual Machine) virtual cpu setup. An unprivileged local user could exploit this flaw to crash the system leading to a denial of service. Steve Grubb reported a flaw with Linux fscaps (file system base capabilities) when used to increase the permissions of a process. For application on which fscaps are in use a local attacker can disable address space randomization to make attacking the process with raised privileges easier. Various other issues were also addressed.</description>
<category></category>
</item>
<item>
<title>Ubuntu Security Notice USN-1447-1</title>
<link>http://packetstormsecurity.org/files/112910/USN-1447-1.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112910/USN-1447-1.txt</guid>
<comments>http://packetstormsecurity.org/files/112910/Ubuntu-Security-Notice-USN-1447-1.html</comments>
<pubDate>Tue, 22 May 2012 00:25:14 GMT</pubDate>
<description>Ubuntu Security Notice 1447-1 - Juri Aedla discovered that libxml2 contained an off by one error in its XPointer functionality. If a user or application linked against libxml2 were tricked into opening a specially crafted XML file, an attacker could cause the application to crash or possibly execute arbitrary code with the privileges of the user invoking the program.</description>
<category></category>
</item>
<item>
<title>Red Hat Security Advisory 2012-0683-01</title>
<link>http://packetstormsecurity.org/files/112909/RHSA-2012-0683-01.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112909/RHSA-2012-0683-01.txt</guid>
<comments>http://packetstormsecurity.org/files/112909/Red-Hat-Security-Advisory-2012-0683-01.html</comments>
<pubDate>Tue, 22 May 2012 00:24:55 GMT</pubDate>
<description>Red Hat Security Advisory 2012-0683-01 - The dynamic LDAP back end is a plug-in for BIND that provides back-end capabilities to LDAP databases. It features support for dynamic updates and internal caching that help to reduce the load on LDAP servers. A flaw was found in the way bind-dyndb-ldap handled LDAP query errors. If a remote attacker were able to send DNS queries to a named server that is configured to use bind-dyndb-ldap, they could trigger such an error with a DNS query leveraging bind-dyndb-ldap&#39;s insufficient escaping of the LDAP base DN. This would result in an invalid LDAP query that named would retry in a loop, preventing it from responding to other DNS queries. With this update, bind-dyndb-ldap only attempts to retry one time when an LDAP search returns an unexpected error. </description>
<category></category>
</item>
<item>
<title>Red Hat Security Advisory 2012-0681-01</title>
<link>http://packetstormsecurity.org/files/112908/RHSA-2012-0681-01.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112908/RHSA-2012-0681-01.txt</guid>
<comments>http://packetstormsecurity.org/files/112908/Red-Hat-Security-Advisory-2012-0681-01.html</comments>
<pubDate>Tue, 22 May 2012 00:23:56 GMT</pubDate>
<description>Red Hat Security Advisory 2012-0681-01 - Apache Tomcat is a servlet container. JBoss Enterprise Web Server includes the Tomcat Native library, providing Apache Portable Runtime support for Tomcat. This update fixes the JBPAPP-4873, JBPAPP-6133, and JBPAPP-6852 bugs. It also resolves multiple flaws that weakened the Tomcat HTTP DIGEST authentication implementation, subjecting it to some of the weaknesses of HTTP BASIC authentication, for example, allowing remote attackers to perform session replay attacks.</description>
<category></category>
</item>
<item>
<title>Red Hat Security Advisory 2012-0679-01</title>
<link>http://packetstormsecurity.org/files/112907/RHSA-2012-0679-01.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112907/RHSA-2012-0679-01.txt</guid>
<comments>http://packetstormsecurity.org/files/112907/Red-Hat-Security-Advisory-2012-0679-01.html</comments>
<pubDate>Tue, 22 May 2012 00:22:52 GMT</pubDate>
<description>Red Hat Security Advisory 2012-0679-01 - Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages technologies. JBoss Enterprise Web Server includes the Tomcat Native library, providing Apache Portable Runtime support for Tomcat. This update includes bug fixes as documented in JBPAPP-4873 and JBPAPP-6133.</description>
<category></category>
</item>
<item>
<title>Red Hat Security Advisory 2012-0682-01</title>
<link>http://packetstormsecurity.org/files/112906/RHSA-2012-0682-01.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112906/RHSA-2012-0682-01.txt</guid>
<comments>http://packetstormsecurity.org/files/112906/Red-Hat-Security-Advisory-2012-0682-01.html</comments>
<pubDate>Tue, 22 May 2012 00:21:41 GMT</pubDate>
<description>Red Hat Security Advisory 2012-0682-01 - Apache Tomcat is a servlet container. JBoss Enterprise Web Server includes the Tomcat Native library, providing Apache Portable Runtime support for Tomcat. This update fixes the JBPAPP-4873, JBPAPP-6133, and JBPAPP-6852 bugs. It also addresses multiple flaws that weakened the Tomcat HTTP DIGEST authentication implementation, subjecting it to some of the weaknesses of HTTP BASIC authentication, for example, allowing remote attackers to perform session replay attacks.</description>
<category></category>
</item>
<item>
<title>Red Hat Security Advisory 2012-0677-01</title>
<link>http://packetstormsecurity.org/files/112905/RHSA-2012-0677-01.txt</link>
<guid isPermaLink="true">http://packetstormsecurity.org/files/112905/RHSA-2012-0677-01.txt</guid>
<comments>http://packetstormsecurity.org/files/112905/Red-Hat-Security-Advisory-2012-0677-01.html</comments>
<pubDate>Tue, 22 May 2012 00:21:29 GMT</pubDate>
<description>Red Hat Security Advisory 2012-0677-01 - PostgreSQL is an advanced object-relational database management system. The pg_dump utility inserted object names literally into comments in the SQL script it produces. An unprivileged database user could create an object whose name includes a newline followed by an SQL command. This SQL command might then be executed by a privileged user during later restore of the backup dump, allowing privilege escalation. CREATE TRIGGER did not do a permissions check on the trigger function to be called. This could possibly allow an authenticated database user to call a privileged trigger function on data of their choosing. </description>
<category></category>
</item>


</channel>
</rss>


