This document is a technical abstract of paper "Win32/Bypass: Anulando la deteccion de ficheros". The main objective is to explain techniques used to bypass security measures of many antivirus programs.
a80051bbb8ce9864fffe9ef392dcd3c70799043f3b62af74e23d40f6777bcba9
Cutenews version 1.3.6 allows for cross site scripting and local code execution attacks. Written in Spanish. Detailed exploitation provided.
4ff35ce512b4b2ef759eb3df6051283b61c8390c04baf6a8e1f1fd0917983380
paNews version 2.0b4 is susceptible to SQL injection and remote code execution attacks. Written in Spanish. Detailed exploitation provided.
51bf414fb60238775ad6c46f6de89f8a906cc9b73db66e117e000228b3b68064
Greymatter 1.3 suffers from script insertion flaws due to a lack of input validation.
da1f5f42b079a3f9904b71392c248b088229d85558c51879520174534f21e8ac
PHP4 cURL functions bypass open_basedir protection allowing users to navigate through the filesystem.
765016dae640f3bcadcb4d07c7fffcebbe55bd3c65241833d9335fe8ef0f2813
The Mambo Open Source web content management system allows for remote command execution as the webserver user id due to a lack of input validation.
da6f8e308f6903ca98dc9383805abc68a8004be17d4c4787d292645cd9e1a4cb
PhpDig version 1.6.x allows for remote command execution in its config.php script. Anybody can inject a url in the relative_script_path variable and obtain command execution with web server privileges.
b24e855c02a2ea8f3937595116627162c9ebfb2051a870e2bd9c0282161bf0f6