Packet Storm new exploits for April, 2004.
742d111c62091254ec064cab105727a130297b31c3e8a6d87832e94e88d4ef34
Sample proof of concept exploit that demonstrates the TCP vulnerability discovered by Paul A. Watson.
498554d722ef08c3079f480800919a02ffb8380999bd74b87840cccf1b571e52
Another program that demonstrates the Rose Attack eating up CPU processing time on a Windows 2000 box.
1762446df8362dce6e172db2a60b849b2bc2e6fe8d05cc34f85b83cfd3bb51b5
Program that demonstrates the Rose Attack eating up CPU processing time on a Windows 2000 box.
1affe79e6026e065c1e1f74743818f1905a9bd31d0c94f82f8de9b88e54adc91
PHP-Nuke Video Gallery Module version 0.1 Beta 5 is susceptible to full path disclosure and SQL injection attacks.
fe3ff118560c7e9a4f76a80601322a0fa94b9f122ffbe84c9212355bc5ab8523
Linux root and Windows NT/2000 Administrator remote exploit for HP Web JetAdmin 6.5.
2313f6c8c3680934ff278d70f97559a0358c9851c286921cd3a616b0ad3e2749
Sample proof of concept exploit that demonstrates the TCP vulnerability discovered by Paul A. Watson. Python version.
80fbb1b75432221e765f2f7267fdcea0bd46642b06db40424528f8dc9503f573
Samsung SmartEther switches allow a remote attacker to login as admin without having a correct password. All that is required is that all of the characters that can fit in the buffer for the password be filled.
afe2a7860a1e2e382e42f0ff2b3783ae8f7656865e91fbdfc36859ea6c6103ac
Sample proof of concept exploit that demonstrates the TCP vulnerability discovered by Paul A. Watson. Perl version.
7b8da88a4b120e083cbeadb74aaf609c90eefcbba41d5d768d53613eda9c9800
Linux eXtremail versions 1.5.9 and below remote root exploit that makes use of a format string vulnerability in its logging mechanism.
6036e06b4c58e55a423903721dd48a2c313b1ab18a6383129e59eff5587ec24e
BGP proof of concept denial of service utility that sends out a RST flood to BGP connection providing the attacker has already gained knowledge of the source port and sequence number.
75724ddc4871b67567b3d2d9ff51b68836f03a08c024e4bc90e759626c5b7c21
Sample proof of concept exploit that demonstrates the TCP vulnerability discovered by Paul A. Watson. Some modifications done by J 'Swoop' Barber.
11a7a7653ba15bc40afd9339cc9f0e30434a339fb299c237f1e64007169ff8b5
Sample proof of concept exploit that demonstrates the TCP vulnerability discovered by Paul A. Watson.
2d800d6c605ec72633700b84acf2706bfd9096969a1bf194fabef7a5ea6a6f69
Security Corporation Security Advisory [SCSA-028]: Nuked-KlaN versions b1.4 and b1.5 allows for directory traversal attacks and global variable overwriting.
61a637daf1513ba208db6fc8145428152db635c02705b2f1d85a0fcd7bb18c37
THCIISSLame version 0.2 IIS 5 SSL remote root exploit. Uses a connect back shell.
5ad43a71b7b21cf163e484398cd12888807b5ff949adbd1a23b2639a8c2f060f
Proof of concept exploit for the Unreal engine developed by EpicGames which has a flaw with UMOD where it handles information from files without properly filtering for dangerous characters.
acf47cd35c604868941f36761ff485936586e453b380f23a94c790cf4a995f84
PostNuke 0.726 Phoenix is susceptible to multiple path disclosure and cross site scripting vulnerabilities.
2421cfda93e82828c31ba0e759ac8a875641a6177c67906a0428a997b7c95c75
The phprofession 2.5 module for PostNuke is susceptible to path disclose, cross site scripting, and possible SQL injection attacks.
f1afb06444f45b473086acaefc01e5542aee6857caf546dc7aeb916bde1b06e2
Mambo OS versions 4.5 and 4.6 exploit written in PHP that insets an administrator user into the database.
a2fc44f4482fa74b878d0564d7eb95973e10a36108e84d5af22116e7d3d80daa
This program will reset a TCP connection by guessing a valid sequence number.
ee4592a7693f13a974fc60191dc03c2bacb52cac2c5e420b304e87f7d2855c73
Local root exploit for Squirrelmail's chpasswd utility. Tested on Suse 9. Original bug found by Matias Neiff.
2b92773c507dec11bb83386fb30b5c4db547be150a75c00aec35583c53feee1b
XFree version 4.3.x local root exploit that makes use of the vulnerability that exists in the use of the CopyISOLatin1Lowered() function with the 'font_name' buffer.
5f80619f3d14965d61bcf967f0b26ae2e5d1de37280e8076979c4872b7760af0
Eudora 6.1 still has attachment spoofing flaws along with a Nested MIME DoS vulnerability.
d3024ea6787aa72ecd301f863e452c672b83f691a325455dd8c7f5b291042e9a
Kinesphere Corporation Exchange POP3 e-mail gateway remote exploit that makes use of a buffer overflow.
aa21d34e23c056c9250ad35d4abf58eeff4391ebca64ff0ac12966a256d74237
phpBB modified by PRzemo version 1.8 allows for arbitrary code execution due to improper filtering allowing for remote script inclusion.
8f915afa29d6d3113d81ad61be80a1976bff508961eda81a442555fabb47b0e4