New User, Welcome!     Login

Next Page >>

injects

Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver, Yaws and Boa log escape sequence injection

Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver,
Yaws and Boa log escape sequence injection

 Name              Nginx, Varnish, Cherokee, thttpd, mini-httpd,
                   WEBrick, Orion, AOLserver, Yaws and Boa log escape
                   sequence injection
 Systems Affected  nginx 0.7.64
                   Varnish 2.0.6
                   Cherokee 0.99.30
                   mini_httpd 1.19

Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities

transferring  data across domains, allowing them to interact with each other.

The Anti-XSS filter has been found to have some security holes in the
current implementation. Microsoft decided to filter "Type 1 XSS" which is
free  text send to the server being reflected to the user and therefore
injecting HTML code into the website's page. They chose not to handle
certain situations such as injection into a JavaScript tag space, which
would be extremely difficult to filter. The software giant also chose not
to filter injection into HTTP headers, which will drive hackers to focus on
discovering CRLF vulnerabilities.


[waraxe-2009-SA#074] - Multiple Vulnerabilities in TorrentTrader Classic 1.09

List of found vulnerabilities
===============================================================================

1. Sql Injection vulnerability in "account-inbox.php"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Reasons:
  1. unsanitized user submitted parameter "origmsg" is used in sql query
Preconditions:

Multiple Adobe Products - XML External Entity And XML Injection Vulnerabilities

                  _='`"``=.

                presents..

Multiple Adobe Products
XML External Entity And XML Injection Vulnerabilities

CVE: CVE-2009-3960
Adobe PSIRT: APSB10-05 - http://www.adobe.com/support/security/bulletins/apsb10-05.html
Link: http://www.security-assessment.com/files/advisories/2010-02-22_Multiple_Adobe_Products-XML_External_Entity_and_XML_Injection.pdf


Pligg <= 9.9.0 Multiple Vulnerabilities

Description:
Pligg is a popular open source, full featured, content management
system written in php. There are a number of vulnerabilities
within Pligg that allow for remote file enumeration, file inclusion,
cross site scripting, and sql injection. When combined these issues
allow for remote code execution on the affected installation
via arbitrary php code placed within template files once admin
credentials are gained via SQL Injection.



BLIND SQL INJECTION--Leap CMS 0.1.4-->

#!/usr/bin/perl
#-----------------------------------------------
#BLIND SQL INJECTION--Leap CMS 0.1.4-->
#-----------------------------------------------
#
#  CMS INFORMATION:
#
#-->WEB: http://leap.gowondesigns.com/
#-->DEMO: http://php.opensourcecms.com/scripts/details.php?scriptid=161&name=Leap
#-->CATEGORY: CMS / Lite

BLIND SQL INJECTION EXPLOIT--TemaTres 1.0.3-->

#!/usr/bin/perl
#---------------------------------------------------
#BLIND SQL INJECTION EXPLOIT--TemaTres 1.0.3-->
#---------------------------------------------------
#
#CMS INFORMATION:
#
#-->WEB: http://www.r020.com.ar/tematres/
#-->DOWNLOAD: http://sourceforge.net/projects/tematres/
#-->DEMO: http://www.r020.com.ar/tematres/index.php

[InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities

AdPeeps Ad Rotator - XSS and HTML Injection Vulnerabilities

Version Affected: 8.5d1 (3-18-09) (newest)

Info: Ad Peeps is a banner rotator and text ad rotator - all in one that allows you to track, sell and manage   banner ads, rich-media/flash ads  and  text ads on your website. Built using PHP/MYSQL, Ad Peeps provides you and your advertisers with highly detailed real-time statistics and is capable of delivering millions of impressions per day on a typical shared web server. -  Plus, you can try it right now on your website with our 7 day trial.

Ad Peeps is so versatile that it can even show your text ads Yahoo! Style or Google AdWords Style. Unlike many other banner ad rotator programs, Ad Peeps was skillfully designed to use minimal server resources while maintaining speed and unparalleled performance. Built on a highly scalable and versatile database architecture, Ad Peeps works without fuss even on high traffic web sites and won't crash your high powered website..

Opinion: AdPeeps, along with many others should really hire people to audit their code.


Xigla Multiple Products - Multiple Vulnerabilities

####################
2. Vulnerabilities:
####################
    2.1. Absolute Live Support XE (ASP version 5.1) (admin)
                2.1.1. SQL Injection in "search.asp" by "orderby" parameter.
                        POC: 
                                http://[URL]/xlaabsolutels/search.asp?orderby=[SQL INJECTION]
                        
                2.1.2. XSS in "search.asp" (all fields are vulnerable).
                        POC:

Cacti 0.8.7a Multiple Vulnerabilities

multiple data acquisition methods, and user management features out of
the box".
 
II. DESCRIPTION
 
Multiple vulnerabilities exist in Cacti software (XSS, SQL Injection,
Path Disclosure, HTTP Response Splitting).
 
III. ANALYSIS
 
Summary:

Theeta CMS (Cross Site Scripting,SQL Injection) Multiple Vulnerabilities

#                                             +-+-+-+-+          #
#                                             |C|r|e|w|          #
#                                             +-+-+-+-+          #
##################################################################
##################################################################
# [#] Theeta CMS (Cross Site Scripting,SQL Injection) Multiple Vulnerabilities  #
# [#] Discovered By c0dy                                         #
# [#] http://r00tDefaced.net                                     #
# [#] Greetz: sHoKeD-bYte, syst0x1c & r00tDefaced Members        #
##################################################################
#

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Agent

Summary
=======

The Management Center for Cisco Security Agents is affected by a
directory traversal vulnerability and a SQL injection vulnerability.
Successful exploitation of the directory traversal vulnerability may
allow an authenticated attacker to view and download arbitrary files
from the server hosting the Management Center. Successful
exploitation of the SQL injection vulnerability may allow an
authenticated attacker to execute SQL statements that can cause

[RT-SA-2009-003] IceWarp WebMail Server: SQL Injection in Groupware Component

Advisory: IceWarp WebMail Server: SQL Injection in Groupware Component

During a penetration test RedTeam Pentesting discovered multiple
SQL-Injections in the IceWarp WebMail Server. Attackers that are in
control of a user account for the web-based email and groupware
components are able to execute arbitrary SQL SELECT statements and
therefore read any data from the DBMS that are accessible by the Icewarp
eMail Server.



Pooya Site Builder (PSB) SQL Injection Vulnerabilities

########################## www.BugReport.ir #######################################
#
#               AmnPardaz Security Research Team
#
# Title: Pooya Site Builder (PSB) SQL Injection Vulnerabilities
# Vendor: www.paridel.com
# Vulnerable Version: 6.0 (Assembly Version)
# Exploit: Available
# Impact: High
# Fix: N/A

Aruba Advisory ID: AID-020810 TLS Protocol Session Renegotiation Security Vulnerability

SUMMARY

This advisory addresses the renegotiation related vulnerability
disclosed recently in Transport Layer Security protocol [1][2]. This
vulnerability may allow a Man-in-the-Middle (MITM) attacker to inject
arbitrary data into the beginning of the application protocol stream
protected by TLS.

The only ArubaOS component that seems affected by this issue is the
HTTPS WebUI administration interface. If a client browser (victim) is

Opera Stored Cross Site Scripting Vulnerability

08-10-22_Opera_Stored_Cross_Site_Scripting.pdf

== Issue Details ==

Opera browser is vulnerable to stored Cross Site
Scripting.  A malicious attacker is able to inject
arbitrary browser content through the
websites visited with the Opera browser. The code
injection is rendered into the Opera History Search
page which displays URL and a short
description of the visited pages.

Attack Technique: File Download Injection

File Download Injection
=======================

Affects most web application platforms, including Java, .NET, PHP, Cold
Fusion.

This attack involves the use of header injection, particularly the
Content-Disposition header, to subvert HTTP responses from trusted
domains. Attackers can use this technique to inject a malicious file
download with an arbitrary filename (.html, .exe, .swf, .mov, .msi,

Invision Power Board <= 3.0.4 Local PHP File Inclusion and SQL Injection

- Severity: Moderately High
=============================================

I. VULNERABILITY
-------------------------
Invision Power Board <= 3.0.4 Local PHP File Inclusion and SQL Injection
Invision Power Board <= 2.3.6 SQL Injection

II. BACKGROUND
-------------------------
Invision Power Board (IPB) is a professional forum system that has  

[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10

[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10
===============================================================================

Author: Janek Vind "waraxe"
Date: 16. January 2008
Location: Estonia, Tartu
Web: http://www.waraxe.us/advisory-62.html



(POST var 'resetpwemail') BLIND SQL INJECTION EXPLOIT --AlumniServer v-1.0.1-->

#!/usr/bin/python
#--------------------------------------------------------------------------------
#(POST var 'resetpwemail') BLIND SQL INJECTION EXPLOIT --AlumniServer v-1.0.1-->
#--------------------------------------------------------------------------------
#
#CMS INFORMATION:
#
#-->WEB: http://www.alumniserver.net/
#-->DOWNLOAD: http://www.alumniserver.net/
#-->DEMO: N/A

WysGui CMS 1.2 BETA(Insecure Cookie Handling)--Blind-sql-injection-exploit-->

#
#  CMS VULNERABILITY:
#
#-->TESTED ON: firefox 3
#-->DORK: N/A
#-->CATEGORY: BLIND SQL INJECTION/ PERL EXPLOIT
#-->AFFECT VERSION: LAST = 1.2 BETA (Maybe <= ?)
#-->Discovered Bug date: 2009-04-20
#-->Reported Bug date: 2009-04-20
#-->Fixed bug date: Not fixed
#-->Info patch (????): Not fixed

Eshopbuilde CMS SQL Injection Vulnerability

================= IUT-CERT =================

Title: Eshopbuilde CMS SQL Injection Vulnerability

Vendor: www.eshopbuilder.ir

Dork: Design by Satcom Co
Type: Input.Validation.Vulnerability (SQL Injection)

Fix: N/A

BLIND SQL INJECTION exploit (GET var 'AlbumID')--RTWebalbum 1.0.462-->

#!/usr/bin/perl
#-----------------------------------------------------------------
#BLIND SQL INJECTION (GET var 'AlbumID')--RTWebalbum 1.0.462-->
#-----------------------------------------------------------------
#
#CMS INFORMATION:
#
#-->WEB: http://rtwebalbum.x12.pl/
#-->DOWNLOAD: http://sourceforge.net/projects/rtwebalbum/
#-->DEMO: http://rtwebalbum.x12.pl/

CLAN TIGER CMS--(module custompage.php) BLIND SQL INJECTION-->

#!/usr/bin/perl
#
#-------------------------------------------------
# (module custompage.php) BLIND SQL INJECTION                        
#-------------------------------------------------
#
# CMS INFORMATION:                              
#
#-->WEB: http://www.clantiger.com
#-->DOWNLOAD: http://www.clantiger.com/download-clan-cms

PHP Security Framework: Vuln and Security Bypass

 Released on:   2007/12/16
   Changelog:   2007/12/16

     Summary:   [HT] Remote File Inclusion
                [MT] SQL Injection
                [MT] SQL Injection Protection Bypass
                [__] Conclusion

      Legend:   L - Low risk         M - Medium risk
                H - High risk        T - Tested

REVISION: iScripts EasySnaps 2.0 Multiple SQL Injection Vulnerabilities

iScripts EasySnaps 2.0 Multiple SQL Injection Vulnerabilities

 Name              iScripts EasySnaps
 Vendor            http://www.iscripts.com
 Versions Affected 2.0

 Author            Salvatore Fresta aka Drosophila
 Website           http://www.salvatorefresta.net
 Contact           salvatorefresta [at] gmail [dot] com
 Date              2010-01-07

CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information

June 2009 [9].

A vulnerability was found in the way that WordPress handles some URL
requests. This results in unprivileged users viewing the content of
plugins configuration pages, and also in some plugins modifying plugin
options and injecting JavaScript code. Arbitrary native code may be run
by a malicious attacker if the blog administrator runs injected
JavasScript code that edits blog PHP code. Many WordPress-powered blogs,
hosted outside 'wordpress.com', allow any person to create unprivileged
users called subscribers. Other sensitive username information
disclosures were found in WordPress.

[DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities

Description
***********

Blogcms system has multiple security vulnerabilities:

1. Multiple SQL Injections
2. Multiple Linked XSS
3. Multiple Linked SiXSS




Hosting Controller - Multiple Security Bugs (Extremely Critical)

1- [Remote Attacker] can login to hosting controller Panel. He can also change all others' passwords. 
2- [User] can copy a file to hosting controller web directory which is executed under administrative privilege, so attacker can execute his commands by administrative privilege. e.g. an attacker can gain remote desktop of server using this bug and uploading an ASP file!
3- [Remote Attacker] can make a new user.
4- [Remote Attacker] can change all user's profiles.
5- [User] can see all the database information by a SQL injection.
6- [User] can change his credit amount or increase his discount.
7- [User] can uninstall other's FrontPage extensions.
8- [User] can delete all of gateway information.
9- [User] can enable or disable pay type.
10- [[User] can see all usernames in the server by "fp2000/NEWSRVR.asp".

(Post Form var 'username') BLIND SQLi exploit --S-CMS <= v-2.0 Beta3-->

#-------
#
#Valid username
#
#---------------------------------------
#PROOF OF CONCEPT (SQL INJECTION):
#---------------------------------------
#
#POST http://[HOST]/[PATH]/plugin.php?page=your_account.php&mode=passlost HTTP/1.1
#Host: [HOST]
#User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; es-ES; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!