Information Security News and Exploits

Providing you with Security News and Exploits from all over the web.

Entries for January, 2012

[webapps / 0day] – Wordpress Age Verification Plugin <= 0.4 Open Redirect

# Exploit Title: Wordpress Age Verification plugin <= 0.4 Open Redirect
# Date: 2012/01/10
# Dork: inurl:wp-content/plugins/age-verification/age-verification.php
# Author: Gianluca Brindisi (gATbrindi.si @gbrindisi http://brindi.si/g/)
# Software Link: http://downloads.wordpress.org/plugin/age-verification.zip
# Version: 0.4
1) Via GET: http://server/wp-content/plugins/age-verification/age-verification.php?redirect_to=http%3A%2F%2Fwww.evil.com
[...]

Leave a Comment

[webapps / 0day] – Wordpress uCan Post plugin <= 1.0.09 Stored XSS

# Exploit Title: Wordpress uCan Post plugin <= 1.0.09 Stored XSS
# Dork: inurl:/wp-content/plugins/ucan-post/
# Date: 2012/01/18
# Author: Gianluca Brindisi (gATbrindi.si @gbrindisi http://brindi.si/g/)
# Software Link: http://downloads.wordpress.org/plugin/ucan-post.1.0.09.zip
# Version: 1.0.09
1) You need permissions to [...]

Leave a Comment

[webapps / 0day] – appRain CMF <= 0.1.5 (uploadify.php) Unrestricted File Upload Exploit

<?php
/*
———————————————————————
appRain CMF <= 0.1.5 (uploadify.php) Unrestricted File Upload Exploit
———————————————————————
author…………: Egidio Romano aka EgiX
[...]

Leave a Comment

[remote exploits] – Avaya WinPDM UniteHostRouter <= 3.8.2 Pre-Auth Command Execute

# Abysssec Public Exploit
# more info www.abysssec.com
# Avaya WinPDM UniteHostRouter <= 3.8.2 Remote Pre-Auth Command Execute
#A boundary error in the Unite Host Router service (UniteHostRouter.exe)
#when processing certain requests can be exploited to cause a stack-based buffer
[...]

Leave a Comment

[webapps / 0day] – AllWebMenus < 1.1.9 WordPress Menu Plugin Arbitrary File Upload

#Exploit Title: AllWebMenus WordPress Menu Plugin Arbitrary file upload
#Version: < 1.1.9
#Date: 2012-01-19
#Author: 6Scan (http://6scan.com) security team
#Software Link: http://wordpress.org/extend/plugins/allwebmenus-wordpress-menu-plugin/
#Official fix: This advisory is released after the vendor was contacted and fixed the issue promptly.
[...]

Leave a Comment

[webapps / 0day] – miniCMS v1.0 => v2.0 Arbitrary File Upload

Source: http://www.1337day.com/exploits/17420

Leave a Comment

[local exploits] – Mempodipper – Linux Local Root for >=2.6.39, 32-bit and 64-bit

Exploit code is here: http://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c
Blog post about it is here: http://blog.zx2c4.com/749
# Exploit Title: Mempodipper – Linux Local Root for >=2.6.39, 32-bit and 64-bit
# Date: Jan 21, 2012
# Author: zx2c4
# Tested on: Gentoo, Ubuntu
[...]

Leave a Comment

[webapps / 0day] – WordPress <= 3.3.1 Multiple Vulnerabilities

Trustwave’s SpiderLabs Security Advisory TWSL2012-002:
Multiple Vulnerabilities in WordPress
Published: 1/24/12
Version: 1.0
Vendor: WordPress (http://wordpress.org/)
Product: WordPress
Version affected: 3.3.1 and prior
Product description:
WordPress is a free and open [...]

Leave a Comment

[webapps / 0day] – Peel SHOPPING => v2.9 xss/sql injection vulnerability

+————————————————————————-+
# Exploit Title : Peel SHOPPING – version 2.8 and version 2.9 xss/sql inject Vulnerability
# version : v2.9
# Author : Cyber-Crystal
# Date [...]

Leave a Comment

[webapps / 0day] – vBSEO <= 3.6.0 "proc_deutf()" Remote PHP Code Injection Exploit

require ‘msf/core’
class Metasploit3 < Msf::Exploit::Remote
include Msf::Exploit::Remote::HttpClient
def initialize(info = {})
super(update_info(info,
[...]

Leave a Comment

[webapps / 0day] – Joomla Component com_propertylab (showproperty&id=) SQL injection

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ [...]

Leave a Comment

[webapps / 0day] – Wordpress Age Verification Plugin <= 0.4 Open Redirect

# Exploit Title: Wordpress Age Verification plugin <= 0.4 Open Redirect
# Date: 2012/01/10
# Dork: inurl:wp-content/plugins/age-verification/age-verification.php
# Author: Gianluca Brindisi (gATbrindi.si @gbrindisi http://brindi.si/g/)
# Software Link: http://downloads.wordpress.org/plugin/age-verification.zip
# Version: 0.4
1) Via GET: http://server/wp-content/plugins/age-verification/age-verification.php?redirect_to=http%3A%2F%2Fwww.evil.com
[...]

Leave a Comment

[webapps / 0day] – Wordpress uCan Post plugin <= 1.0.09 Stored XSS

# Exploit Title: Wordpress uCan Post plugin <= 1.0.09 Stored XSS
# Dork: inurl:/wp-content/plugins/ucan-post/
# Date: 2012/01/18
# Author: Gianluca Brindisi (gATbrindi.si @gbrindisi http://brindi.si/g/)
# Software Link: http://downloads.wordpress.org/plugin/ucan-post.1.0.09.zip
# Version: 1.0.09
1) You need permissions to [...]

Leave a Comment

[webapps / 0day] – appRain CMF <= 0.1.5 (uploadify.php) Unrestricted File Upload Exploit

<?php
/*
———————————————————————
appRain CMF <= 0.1.5 (uploadify.php) Unrestricted File Upload Exploit
———————————————————————
author…………: Egidio Romano aka EgiX
[...]

Leave a Comment

[remote exploits] – Avaya WinPDM UniteHostRouter <= 3.8.2 Pre-Auth Command Execute

# Abysssec Public Exploit
# more info www.abysssec.com
# Avaya WinPDM UniteHostRouter <= 3.8.2 Remote Pre-Auth Command Execute
#A boundary error in the Unite Host Router service (UniteHostRouter.exe)
#when processing certain requests can be exploited to cause a stack-based buffer
[...]

Leave a Comment

[webapps / 0day] – AllWebMenus < 1.1.9 WordPress Menu Plugin Arbitrary File Upload

#Exploit Title: AllWebMenus WordPress Menu Plugin Arbitrary file upload
#Version: < 1.1.9
#Date: 2012-01-19
#Author: 6Scan (http://6scan.com) security team
#Software Link: http://wordpress.org/extend/plugins/allwebmenus-wordpress-menu-plugin/
#Official fix: This advisory is released after the vendor was contacted and fixed the issue promptly.
[...]

Leave a Comment

[webapps / 0day] – miniCMS v1.0 => v2.0 Arbitrary File Upload

Source: http://www.1337day.com/exploits/17420

Leave a Comment

[local exploits] – Mempodipper – Linux Local Root for >=2.6.39, 32-bit and 64-bit

Exploit code is here: http://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c
Blog post about it is here: http://blog.zx2c4.com/749
# Exploit Title: Mempodipper – Linux Local Root for >=2.6.39, 32-bit and 64-bit
# Date: Jan 21, 2012
# Author: zx2c4
# Tested on: Gentoo, Ubuntu
[...]

Leave a Comment

[webapps / 0day] – WordPress <= 3.3.1 Multiple Vulnerabilities

Trustwave’s SpiderLabs Security Advisory TWSL2012-002:
Multiple Vulnerabilities in WordPress
Published: 1/24/12
Version: 1.0
Vendor: WordPress (http://wordpress.org/)
Product: WordPress
Version affected: 3.3.1 and prior
Product description:
WordPress is a free and open [...]

Leave a Comment

[webapps / 0day] – Peel SHOPPING => v2.9 xss/sql injection vulnerability

+————————————————————————-+
# Exploit Title : Peel SHOPPING – version 2.8 and version 2.9 xss/sql inject Vulnerability
# version : v2.9
# Author : Cyber-Crystal
# Date [...]

Leave a Comment