This module exploits a heap overflow vulnerability in Internet Explorer caused by an incorrect handling of the span attribute for col elements from a fixed table, when they are modified dynamically by javascript code.
This module exploits a vulnerability found in WebPageTest's Upload Feature. By default, the resultimage.php file does not verify the user-supplied item before saving it to disk, and then places this item in the web directory accessable by remote users. This flaw can be abused to gain remote code execution.
The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms without user inter action.
Movm is a joomla extension for mobiles which optimize VirtueMart sites for iphone, android and blackberry. It is compatible with Joomla2.5 and VirtueMart 2.0. This component can be Attacked from a mobile, put the following string in the url field: p0C http://server/index.php?option=com_movm&controller=product&task=product&id=999999'+UNION+ALL+SELECT+1%2C2%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10%2Cdatabase()+FROM+information_schema.schemata--+D4NB4R%20
pBot is a PHP IRC bot that is vulnerable to remote code execution due to the use of an insecure hostauth value. An attacker can send a malicious payload to the bot, which will then be executed on the server. This payload can be used to delete the bot's originating script, and cause the bot to die.
On the 24th of February 2010 a patch was provided to the main Glibc tree which added optimisation support for 64 bit processors by adding unsigned conditional jumps to support > 2GB data sizes. If an attacker could control the length parameter supplied memcpy, it may be possible to cause the application to execute user controllable code. This has been verified and tested on a fully patched and up to date installation of Ubuntu 10.4 LTS against various applications. When this is the case, an attacker controllable length value is used to calculate the jump table pointer index in the optimized copy function. Setting the length value to a negative number will cause a jmp instruction to be skipped due to an signedness vulnerbility, resulting in attacker supplied value being used to calculate the location of a jump table function, resulting in malicious code execution.
There is a SQL Injection vulnerability that can be called from within the website to perform the SQL Injection attack. The impact of this vulnerability should be rated as critical as it is possible to access the database and therefore retrieve user information such as usernames, passwords and other data. When abused, hackers could gain access to the administrative interface of Joomla.
Dr. Web Enterprise Security Suite is managed via a web based interface called Control Center. If an attacker suplies java script code instead of a username on the login page, this script code will be automatically executed every time an administrative user is viewing the audit log. This attack can be used to steal authentication cookies or to drive further attacks.
This exploit is a proof of concept for a Blind SQL Injection vulnerability. It attempts to dump out the first available hash in the users table of spywall_db. It does this by sending a series of requests to the server, each of which contains a different value for a single character in the hash. If the request takes longer than the specified time, the value is assumed to be correct. The exploit then moves on to the next character in the hash.
This module exploits a vulnerability found in SharePoint Server 2007 SP2. The software contains a directory traversal, that allows a remote attacker to write arbitrary files to the filesystem, sending a specially crafted SOAP ConvertFile request to the Office Document Conversions Launcher Service, which results in code execution under the context of 'SYSTEM'. The module uses uses the Windows Management Instrumentation service to execute an arbitrary payload on vulnerable installations of SharePoint on Windows 2003 Servers.