Archive for the 'Security & Exploit News' Category

PR07-40.txt

The 3Com AP 8760 suffers from authentication bypass, password leakage, and SNMP injection vulnerabilities. Details provided.

punbb-lfi.txt

PunBB (Private Messaging System versions 1.2.x) multiple local file inclusion exploit.

mytopix-sql.txt

MyTopix versions 1.3.0 and below remote SQL injection exploit.

msvista-overflow.txt

The Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory. Proof of concept test code included.

easyeditcms-sql.txt

Easyedit CMS suffers from multiple remote SQL injection vulnerabilities.

ethiclinks-sql.txt

Ethiclinks suffers from a remote SQL injection vulnerability.

linksxs-sql.txt

Linksxs Script suffers from a remote SQL injection vulnerability.

linksautomation-sql.txt

LinksAutomation Script suffers from a remote SQL injection vulnerability.

maurycms-upload.txt

MauryCMS versions 0.53.2 and below remote shell upload exploit.

revsense-sql.txt

RevSense suffers from a remote SQL injection vulnerability that allows for authentication bypass.