<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title>安全文章</title>
<link>http://www.vfocus.net/art/index.html</link>
<description>安全文章</description>
<language>zh-cn</language>
<generator>CopyRight&amp;nbsp;&amp;copy;&amp;nbsp;2002-2008 &lt;a href=&quot;/&quot; target=_blank title=&quot;:::VITTERSAFE危特网安:::&quot;&gt;VFocuS.Net&lt;/a&gt; All Rights Reserved</generator>
<webmaster>webmaster@mail.securitycn.net</webmaster>
<item>
    <title>Discuz! Reset User Password Vulnerability</title>
    <link>http://www.vfocus.net/art/20081121/4145.html</link>
    <description>Discuz! Reset User Password Vulnerabilityauthor: 80vul-A/80vul-Bteam:http://www.80vul.com由于Discuz! 的随机数使用的播种缺陷,在找会用户密码时可以暴力得到id的随机hash,从而导致容易修改用户密码的严重漏洞.一 分析暂缺[将在pstzine3上详细介绍这个问题,有兴趣</description>
    <pubDate>2008-11-21</pubDate>
    <category>Exploits</category>
    <author>80vul-A</author>
    <comments>http://www.80vul.com</comments>
</item>
<item>
    <title>Oracle Database Vault  ptrace(2) Privilege Escalation Exploit</title>
    <link>http://www.vfocus.net/art/20081121/4144.html</link>
    <description>/* * original release: http://vnull.pcnet.com.pl/blog/?p=92 * * ora_dv_mem_off.c version 0x1 * ORACLE Database Vault runtime disabler (x86_32 Linux only) * AKA give_back_the_freedom * by Jakub 'vnull' Wartak jakub.wartak@gmail.com 26.02.2008 * 0-day</description>
    <pubDate>2008-11-21</pubDate>
    <category>Exploits</category>
    <author>Jakub</author>
    <comments>jakub.wartak@gmail.com</comments>
</item>
<item>
    <title>vBulletin 3.7.3 Visitor Message XSS/XSRF + worm Exploit</title>
    <link>http://www.vfocus.net/art/20081121/4143.html</link>
    <description>/* ----------------------------- * Author = Mx * Title = vBulletin 3.7.3 Visitor Messages XSS/XSRF + worm * Software = vBulletin * Addon = Visitor Messages * Version = 3.7.3 * Attack = XSS/XSRF - Description = A critical vulnerability exists in the n</description>
    <pubDate>2008-11-21</pubDate>
    <category>Exploits</category>
    <author>Mx</author>
    <comments>www.vfcocus.net</comments>
</item>
<item>
    <title>PHP-Fusion 7.00.1 (messages.php) Remote SQL Injection Exploit</title>
    <link>http://www.vfocus.net/art/20081121/4142.html</link>
    <description>?php /*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-* PHP-Fusion 7.00.1 (messages.php) Remote SQL Injection Exploit requires magic_quotes == off coded by irk4z[at]yahoo.pl homepage: http://irk4z.wordpress.com greets: all</description>
    <pubDate>2008-11-21</pubDate>
    <category>Exploits</category>
    <author>irk4z</author>
    <comments>http://irk4z.wordpress.com</comments>
</item>
<item>
    <title>wPortfolio &lt;= 0.3 Admin Password Changing Exploit</title>
    <link>http://www.vfocus.net/art/20081121/4141.html</link>
    <description>?php /* ============================================================================== _ _ _ _ _ _ /  | | | | /  | | | | / _  | | | | / _  | |_| | / ___  | |___ | |___ / ___  | _ | IN THE NAME OF /_/ _ |_____| |_____| /_/ _ |_| |_| ========</description>
    <pubDate>2008-11-21</pubDate>
    <category>Exploits</category>
    <author>G4N0K</author>
    <comments>mail.ganok[at]gmail.com</comments>
</item>
<item>
    <title>PunBB Mod PunPortal 0.1 Local File Inclusion Exploit</title>
    <link>http://www.vfocus.net/art/20081121/4140.html</link>
    <description>#!/usr/bin/perl =about PunBB (PunPortal 0.1) Local File Inclusion Exploit -------------------------------------------------- by athos - staker[at]hotmail[dot]it download mod http://www.punres.org/download.php?id=1108 download cms http://punbb.org reg</description>
    <pubDate>2008-11-21</pubDate>
    <category>Exploits</category>
    <author>athos</author>
    <comments>staker[at]hotmail[dot]it</comments>
</item>
<item>
    <title>Exodus 0.10 (uri handler) Arbitrary Parameter Injection Exploit</title>
    <link>http://www.vfocus.net/art/20081121/4139.html</link>
    <description>!-- Exodus v0.10 remote code execution exploit by Nine:Situations:Group::strawdog This uses the -l argument to overwrite a file inside Microsoft Help and Support Center folders (oh rgod...) Firstly run netcat in listen mode to drop the vbscript shell</description>
    <pubDate>2008-11-21</pubDate>
    <category>Exploits</category>
    <author>strawdog</author>
    <comments>Nine:Situations:Group::strawdog</comments>
</item>
<item>
    <title>Portfolio &lt;= 0.3 Remote Arbitrary File Upload Exploit</title>
    <link>http://www.vfocus.net/art/20081120/4138.html</link>
    <description>#!/usr/bin/perl # Name: wPortfolio = 0.3 Arbitrary File Upload Exploit # Script Name: wPortfolio 0.3 # Download: http://sourceforge.net/project/downloading.php?group_id=244834use_mirror=kentfilename=wPortfolio.zip80791070 # Vulnerability: Arbitrary F</description>
    <pubDate>2008-11-20</pubDate>
    <category>Exploits</category>
    <author>Osirys</author>
    <comments>osirys[at]live[dot]it</comments>
</item>
<item>
    <title>Exploits Microsoft VISTA TCP/IP stack buffer overflow</title>
    <link>http://www.vfocus.net/art/20081120/4137.html</link>
    <description>#define _WIN32_WINNT 0x0600#define WIN32_LEAN_AND_MEAN#include windows.h#include winsock2.h#include ws2ipdef.h#include iphlpapi.h#include stdio.h#include stdlib.hint main(int argc, char** argv){ DWORD dwStatus; MIB_IPFORWARD_ROW2 route; if (argc !=</description>
    <pubDate>2008-11-20</pubDate>
    <category>Exploits</category>
    <author>Unterleitner</author>
    <comments>t.unterleitner_(at)_phion.com</comments>
</item>
<item>
    <title>MauryCMS &lt;= 0.53.2 Remote Shell Upload Exploit</title>
    <link>http://www.vfocus.net/art/20081120/4136.html</link>
    <description>#!/usr/bin/perl =about MauryCMS = 0.53.2 Remote Shell Upload Exploit ---------------------------------------------- by athos - staker[at]hotmail[dot]it download on http://cms.maury91.org thnx Osirys =cut use strict; use warnings; use LWP::UserAgent;</description>
    <pubDate>2008-11-20</pubDate>
    <category>Exploits</category>
    <author>athos</author>
    <comments>staker[at]hotmail[dot]it</comments>
</item>
<item>
    <title>MyTopix &lt;= 1.3.0 (notes send) Remote SQL Injection Exploit</title>
    <link>http://www.vfocus.net/art/20081120/4135.html</link>
    <description>?php /** * * MyTopix = 1.3.0 (notes send) Remote SQL Injection Exploit * Bug discovered exploited by cOndemned * * Desc : *In order to exploit this vulnerability user have to *be logged on the forum, so I'd decided to write this *exploit x] * * Greet</description>
    <pubDate>2008-11-20</pubDate>
    <category>Exploits</category>
    <author>cOndemned</author>
    <comments>www.vfcocus.net</comments>
</item>
<item>
    <title>PunBB (Private Messaging System 1.2.x) Multiple LFI Exploit</title>
    <link>http://www.vfocus.net/art/20081120/4134.html</link>
    <description>?php error_reporting(0); ini_set(default_socket_timeout,5); /* PunBB (Private Messaging System 1.2.x) Multiple LFI Exploit ----------------------------------------------------------- by athos - staker[at]hotmail[dot]it download mod http://www.punres.</description>
    <pubDate>2008-11-20</pubDate>
    <category>Exploits</category>
    <author>athos</author>
    <comments>staker[at]hotmail[dot]it</comments>
</item>
<item>
    <title>Chilkat Socket activex 2.3.1.1 Remote Arbitrary File Creation Exploit</title>
    <link>http://www.vfocus.net/art/20081118/4133.html</link>
    <description>html titleChilkatSocket.DLL Arbitrary File Creation/titlebrbr body Company Name : Chilkat Software, Inc.brbr Vulnerable DLL : ChilkatSocket.DLLbrbr DLL's version : 2,3,1,1brbr Object Safety Report : br Report for Clsid: {474FCCCD-1B89-4D34-9E09-45807</description>
    <pubDate>2008-11-18</pubDate>
    <category>Exploits</category>
    <author>Underz0ne</author>
    <comments>http://www.underz0ne.org</comments>
</item>
<item>
    <title>FREEze Greetings 1.0 Remote Password Retrieve Exploit</title>
    <link>http://www.vfocus.net/art/20081118/4132.html</link>
    <description>?php /** * FREEze Greetings 1.0 Remote Password Retrieve Exploit * Exploit by cOndemned * * Greetz : suN8Hclf, 0in, m4r1usz, str0ke, rtgn, doctor, sid.psycho [...] * Special thx to ZaBeaTy for developing such a sexy regexp ;) Thx m8 */ echo Header [~</description>
    <pubDate>2008-11-18</pubDate>
    <category>Exploits</category>
    <author>cOndemned</author>
    <comments>www.vfcocus.net</comments>
</item>
<item>
    <title>Opera 9.62 file:// Local Heap Overflow Exploit</title>
    <link>http://www.vfocus.net/art/20081118/4131.html</link>
    <description>html headtitleuh?/title/head body script // k`sOSe 11/15/2008 // tested on Windows XP SP3, opera 9.62 international version // vulnerability found by send9 // there are many ways to achieve code execution, tons of function pointers to overwrite. // m</description>
    <pubDate>2008-11-18</pubDate>
    <category>Exploits</category>
    <author>k`sOSe</author>
    <comments>www.vfcocus.net</comments>
</item>
<item>
    <title>浅析浏览器的跨域安全问题</title>
    <link>http://www.vfocus.net/art/20081117/4130.html</link>
    <description>==Ph4nt0m Security Team== Issue 0x02, Phile #0x04 of 0x0A |=---------------------------------------------------------------------------=| |=-----------------------=[ 浅析浏览器的跨域安全问题 ]=----------------------=| |=-----------------------------</description>
    <pubDate>2008-11-17</pubDate>
    <category>漏洞资料</category>
    <author>ayh4c</author>
    <comments>rayh4c_at_80sec.com</comments>
</item>
<item>
    <title>MS Windows Server Service Code Execution Exploit (MS08-067) (2k/2k3)</title>
    <link>http://www.vfocus.net/art/20081117/4129.html</link>
    <description>#!/usr/bin/env python ############################################################################# # MS08-067 Exploit by Debasis Mohanty (aka Tr0y/nopsled) # www.hackingspirits.com # www.coffeeandsecurity.com # Email: d3basis.m0hanty @ gmail.com ###</description>
    <pubDate>2008-11-17</pubDate>
    <category>Exploits</category>
    <author>Mohanty</author>
    <comments>www.hackingspirits.com</comments>
</item>
<item>
    <title>Minigal b13 (index.php list) Remote File Disclosure Exploit</title>
    <link>http://www.vfocus.net/art/20081117/4128.html</link>
    <description>?php set_time_limit(0); function find_pass($data){ $pass = explode('$adminpass = ',$data); if($pass[1]!=){ echo(Vuln exploited enjoy !n); sleep(1); echo(Admin hash == [.substr($pass[1],0,32).]n); } else{ echo(Exploit failed!!!!); } } function __sen</description>
    <pubDate>2008-11-17</pubDate>
    <category>Exploits</category>
    <author>Luja</author>
    <comments>www.vfcocus.net</comments>
</item>
<item>
    <title>Sudo &lt;= 1.6.9p18 (Defaults setenv) Local Privilege Escalation Exploit</title>
    <link>http://www.vfocus.net/art/20081117/4127.html</link>
    <description>#!/bin/sh #* Sudo = 1.6.9p18 local r00t exploit #* by Kingcope/2008/www.com-winner.com # # Most lame exploit EVER! # # Needs a special configuration in the sudoers file: # --- Defaults setenv so environ vars are preserved :) --- # # May also need the</description>
    <pubDate>2008-11-17</pubDate>
    <category>Exploits</category>
    <author>Kingcope</author>
    <comments>www.com-winner.com</comments>
</item>
<item>
    <title>VeryPDF PDFView OCX ActiveX OpenPDF Heap Overflow PoC</title>
    <link>http://www.vfocus.net/art/20081117/4126.html</link>
    <description>!-- VeryPDF PDFView OCX ActiveX OpenPDF Heap Overflow Discovered Written By: r0ut3r (writ3r [at] gmail.com / www.bmgsec.com.au) Advisory: http://www.bmgsec.com.au/advisory/39/ --------------------------------------------------- Tested on: WinXP Pro S</description>
    <pubDate>2008-11-17</pubDate>
    <category>Exploits</category>
    <author>r0ut3r</author>
    <comments>www.bmgsec.com.au</comments>
</item>
<item>
    <title>SlimCMS &lt;= 1.0.0 (edit.php) Remote SQL Injection Exploit</title>
    <link>http://www.vfocus.net/art/20081115/4124.html</link>
    <description>#!/usr/bin/perl =starting -------------------------------------------------------- SlimCMS = 1.0.0 (edit.php) Remote SQL Injection Exploit -------------------------------------------------------- by athos - staker[at]hotmail[dot]it download on source</description>
    <pubDate>2008-11-15</pubDate>
    <category>Exploits</category>
    <author>athos</author>
    <comments>staker[at]hotmail[dot]it</comments>
</item>
<item>
    <title>Discuz! 6.x/7.x Remote Code Execution Exploit</title>
    <link>http://www.vfocus.net/art/20081115/4123.html</link>
    <description>#!/usr/bin/php?php/** * Discuz! 6.x/7.x SODB-2008-13 Exp * By www.80vul.com * 文件中注释的变量值请自行修改 */$host = 'www.80vul.com';// 服务器域名或IP$path = '/discuz/';// 程序所在的路径$key = 0;// 上面的变量编辑好后，请将此处的值改为1if (strpos($ho</description>
    <pubDate>2008-11-15</pubDate>
    <category>Exploits</category>
    <author>80vul</author>
    <comments>www.80vul.com</comments>
</item>
<item>
    <title>linux/x86 setuid(0) &amp; execve(/bin/sh,0,0) shellcode 27 bytes</title>
    <link>http://www.vfocus.net/art/20081115/4122.html</link>
    <description>-----------[ C Source Code ]----------- /* Smallest GNU/Linux x86 setuid(0) execve(/bin/sh,0,0) Shellcode without NULLs Coded by Chema Garcia (aka sch3m4) + sch3m4@opensec.es + http://opensec.es Shellcode Size: 27 bytes Date: 13/11/2008 */ #include</description>
    <pubDate>2008-11-15</pubDate>
    <category>Exploits</category>
    <author>sch3m4</author>
    <comments>http://opensec.es</comments>
</item>
<item>
    <title>MemHT Portal 4.0.1 SQL Injection Code Execution Exploit</title>
    <link>http://www.vfocus.net/art/20081114/4121.html</link>
    <description>#!/usr/bin/perl =about MemHT 4.0.1 Perl exploit AUTHOR discovered written by Ams ax330d [doggy] gmail [dot] com VULN. DESCRIPTION: Due to weak params filtering we are able to make SQL-Injection. So, 1. Look at 'inc/ajax/ajax_rating.php', line ~ 29. I</description>
    <pubDate>2008-11-14</pubDate>
    <category>Exploits</category>
    <author>Ams</author>
    <comments>ax330d [doggy] gmail [dot] com</comments>
</item>
<item>
    <title>MS Windows Server Service Code Execution Exploit (MS08-067)</title>
    <link>http://www.vfocus.net/art/20081113/4119.html</link>
    <description>/* MS08-067 Remote Stack Overflow Vulnerability Exploit Author: Polymorphours Email: Polymorphours@whitecell.org Homepage:http://www.whitecell.org Date: 2008-10-28 */ #include stdafx.h #include winsock2.h #include Rpc.h #include stdio.h #include stdl</description>
    <pubDate>2008-11-13</pubDate>
    <category>Exploits</category>
    <author>Polymorphours</author>
    <comments>http://www.whitecell.org</comments>
</item>
<item>
    <title>Net-SNMP &lt;= 5.1.4/5.2.4/5.4.1 Perl Module Buffer Overflow PoC</title>
    <link>http://www.vfocus.net/art/20081113/4118.html</link>
    <description>#!usr/bin/perl -w ################################################################################################################ # Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, # as used in SNMP.xs</description>
    <pubDate>2008-11-13</pubDate>
    <category>Exploits</category>
    <author>praveen</author>
    <comments>praveen[underscore]recker[at]sify.com</comments>
</item>
<item>
    <title>Castle Rock Computing SNMPc &lt; 7.1.1 (Community) Remote BOF PoC</title>
    <link>http://www.vfocus.net/art/20081113/4117.html</link>
    <description>#!usr/bin/perl -w ################################################################################################################ # Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and # earlier allows remote att</description>
    <pubDate>2008-11-13</pubDate>
    <category>Exploits</category>
    <author>praveen</author>
    <comments>praveen[underscore]recker[at]sify.com</comments>
</item>
<item>
    <title>Linux Kernel &lt; 2.4.36.9/2.6.27.5 Unix Sockets Local Kernel Panic Exploit</title>
    <link>http://www.vfocus.net/art/20081112/4116.html</link>
    <description>#include sys/socket.h #include sys/un.h #include unistd.h #include assert.h #include err.h #include stdlib.h static int own_child(int *us) { int pid; int s[2]; struct msghdr mh; char crap[1024]; struct iovec iov; struct cmsghdr *c; int *fd; int rc; p</description>
    <pubDate>2008-11-12</pubDate>
    <category>Exploits</category>
    <author>Bittau</author>
    <comments>www.vfcocus.net</comments>
</item>
<item>
    <title>smcFanControl 2.1.2 Multiple Buffer Overflow Vulnerabilities PoC (OSX)</title>
    <link>http://www.vfocus.net/art/20081112/4115.html</link>
    <description>vnsecurity.net ADVISORY 2008-11 =============================== :Title: Buffer overflows in smcFanControl 2.1.2 for OSX :Severity: Critical :Reporter: KaiJern, Lau ( kjlau at vnsecurity.net) :Products: smcFanControl 2.1.2 :OS: OSX :Fixed in: to be re</description>
    <pubDate>2008-11-12</pubDate>
    <category>Exploits</category>
    <author>kjlau</author>
    <comments>kjlau at vnsecurity.net</comments>
</item>
<item>
    <title>ooVoo 1.7.1.35 (URL Protocol) Remote Unicode Buffer Overflow PoC</title>
    <link>http://www.vfocus.net/art/20081112/4114.html</link>
    <description>?php /* ooVoo 1.7.1.35 (URL Protocol) remote unicode buffer overflow poc by Nine:Situations:Group::bruiser tested against IE8b/xp sp3 9sg site: http://retrogod.altervista.org/ software site: http://www.oovoo.com/ description: ooVoo is a startup video</description>
    <pubDate>2008-11-12</pubDate>
    <category>Exploits</category>
    <author>retrogod</author>
    <comments>http://retrogod.altervista.org/</comments>
</item>
<item>
    <title>攻防实战：网络维护过程中的渗透与反渗透</title>
    <link>http://www.vfocus.net/art/20081111/4113.html</link>
    <description>我的一个朋友告诉我，说他们在访问自己公司网站时，出来一大堆东西，而且杀毒软件还提示网页存在病毒， 我的第一感觉就是公司服务器被人入侵了。 （一）网站挂马检测和清除 1.使用软件嗅探被挂马页面 朋友将远程终端和公司网站名称告诉我后，我首先在虚拟机中使用URLSno</description>
    <pubDate>2008-11-11</pubDate>
    <category>网络安全</category>
    <author>陈小兵</author>
    <comments>51CTO.com</comments>
</item>
<item>
    <title>PhpCms2007 sp6 SQL injection 0day (wenba)</title>
    <link>http://www.vfocus.net/art/20081110/4112.html</link>
    <description>? print_r ( ' -------------------------------------------------------------------------------- Phpcms2007(wenba)blindSQLinjection/admincredentialsdisclosureexploit BYoldjun[S.U.S](http://www.oldjun.com) ----------------------------------------------</description>
    <pubDate>2008-11-10</pubDate>
    <category>Exploits</category>
    <author>oldjun</author>
    <comments>http://www.oldjun.com</comments>
</item>
<item>
    <title>Discuz! $_DCACHE数组变量覆盖漏洞</title>
    <link>http://www.vfocus.net/art/20081110/4111.html</link>
    <description>Discuz! ___FCKpd___0 DCACHE数组变量覆盖漏洞author: ryat_at_www.wolvez.orgteam:http://www.80vul.com由于Discuz! 的wapindex.php调用Chinese类里Convert方法在处理post数据时不当忽视对数组的处理,可使数组被覆盖为NULL.当覆盖 ___FCKpd___0 DCACHE时导致导致xss</description>
    <pubDate>2008-11-10</pubDate>
    <category>漏洞资料</category>
    <author>ryat</author>
    <comments>www.wolvez.org</comments>
</item>
<item>
    <title>dedecms gbk版0day</title>
    <link>http://www.vfocus.net/art/20081110/4110.html</link>
    <description>一个月前看了看了dedecms代码（只看了plus下的文件），发现有些变量人为控制没有过滤，但是在php的魔法引号这道天然屏障面前利用几率不好 但是联想到gbk的宽字符，突破方法就有了 漏洞文件：plus/infosearch.php 测试版本：5.1 gbk 描述：$q变量没有过滤直接进入查询，</description>
    <pubDate>2008-11-10</pubDate>
    <category>漏洞资料</category>
    <author>tojen</author>
    <comments>www.tojen.cn</comments>
</item>
<item>
    <title>N种内核注入DLL的思路及实现</title>
    <link>http://www.vfocus.net/art/20081110/4109.html</link>
    <description>Author : sudami [ sudami@163.com ] Time : 01-11-2008 Links : http://hi.baidu.com/sudami 内核注入 ，技术古老但很实用。现在部分 RK 趋向无进程 , 玩的是 SYS+DLL ，有的无文件，全部存在于内存中。可能有部分人会说：都进内核了 . 什么不能干？。是啊，要是内核</description>
    <pubDate>2008-11-10</pubDate>
    <category>入侵实例</category>
    <author>sudami</author>
    <comments>http://hi.baidu.com/sudami</comments>
</item>
<item>
    <title>跨站挂马全攻略</title>
    <link>http://www.vfocus.net/art/20081110/4108.html</link>
    <description>文章作者：a1pass [E.S.T] 信息来源：邪恶八进制信息安全团队（ www.eviloctal.com ） 原始出处： http://a1pass.blog.163.com/ 文章备注：本文发表于《黑客X档案》08年第5期，与原文有少许出入。 现在的黑客攻击手法中，跨站挂马似乎正在逐渐成为攻击的主流话题，鉴于</description>
    <pubDate>2008-11-10</pubDate>
    <category>入侵实例</category>
    <author>a1pass</author>
    <comments>www.eviloctal.com</comments>
</item>
<item>
    <title>Mambo Component n-form (form_id) Blind SQL Injection Exploit</title>
    <link>http://www.vfocus.net/art/20081110/4107.html</link>
    <description>#!/usr/bin/perl use LWP::UserAgent; use Getopt::Long; if(!$ARGV[1]) { system(Title Kosova Hackers Group by boom3rang); print n; print #######################################################################n; print # Mambo Component n-form(form_id)</description>
    <pubDate>2008-11-10</pubDate>
    <category>Exploits</category>
    <author>boom3rang</author>
    <comments>www.khg-crew.ws</comments>
</item>
<item>
    <title>MemHT Portal &lt;= 4.0 Remote Code Execution Exploit</title>
    <link>http://www.vfocus.net/art/20081110/4106.html</link>
    <description>#!/usr/bin/perl =about MemHT Portal = 4.0 Perl exploit AUTHOR: Discovered and written by Ams ax330d [doggy] gmail [dot] com DESCRIPTION: Here we are able to make SQL-injection due to weak filtering. So, look at inc/inc_header.php lines ~ 74, where hi</description>
    <pubDate>2008-11-10</pubDate>
    <category>Exploits</category>
    <author>Ams</author>
    <comments>ax330d [doggy] gmail [dot] com</comments>
</item>
<item>
    <title>GE Proficy Real Time Information Portal Credentials Leak Sniffer (meta)</title>
    <link>http://www.vfocus.net/art/20081110/4105.html</link>
    <description>## # $Id: rtipsniff.rb ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions. Please see the Metasploit # Framework web site for more information on licensing and terms of use. # http</description>
    <pubDate>2008-11-10</pubDate>
    <category>Exploits</category>
    <author>hdm</author>
    <comments>http://metasploit.com</comments>
</item>
<item>
    <title>VLC Media Player &lt; 0.9.6 .RT Stack Buffer Overflow Exploit</title>
    <link>http://www.vfocus.net/art/20081110/4104.html</link>
    <description>#!/usr/bin/perl # VLC Media Player 0.9.6 .RT File Buffer Overflow (Stack Based) # --------------------------------------------------------------- # Exploit by SkD skdrat@hotmail.com # # This should work on a fully up-to-date Windows XP SP3. If you wa</description>
    <pubDate>2008-11-10</pubDate>
    <category>Exploits</category>
    <author>SkD</author>
    <comments>skdrat@hotmail.com</comments>
</item>
<item>
    <title>e-Vision CMS &lt;= 2.0.2 Multiple Local File Inclusion Exploit</title>
    <link>http://www.vfocus.net/art/20081107/4103.html</link>
    <description>?php error_reporting(0); ini_set(default_socket_timeout,5); /* e-Vision = 2.0.2 Multiple Local File Inclusion Exploit ------------------------------------------------------- by athos - download http://sourceforge.net ---------------------------------</description>
    <pubDate>2008-11-07</pubDate>
    <category>Exploits</category>
    <author>StAkeR</author>
    <comments>StAkeR[at]hotmail[dot]it</comments>
</item>
<item>
    <title>Simple Machines Forum &lt;= 1.1.6 (LFI) Code Execution Exploit</title>
    <link>http://www.vfocus.net/art/20081106/4102.html</link>
    <description>#!/usr/bin/perl # # @title: Simple Machines Forum Code Execution # @versn: * = 1.1.6 # @authr: ~elmysterio ( a.k.a us ) # @stats: DROPPED!!!!!!! # @descp: In loving memory of the rare bone marrow disease that killed rgod. # We can't thank you enough</description>
    <pubDate>2008-11-06</pubDate>
    <category>Exploits</category>
    <author>elmysterio</author>
    <comments>www.vfcocus.net</comments>
</item>
<item>
    <title>Adobe Reader util.printf() JavaScript Function Stack Overflow Exploit</title>
    <link>http://www.vfocus.net/art/20081106/4101.html</link>
    <description>Adobe Reader Javascript Printf Buffer Overflow Exploit =========================================================== Reference: http://www.coresecurity.com/content/adobe-reader-buffer-overflow CVE-2008-2992 Thanks to coresecurity for the technical back</description>
    <pubDate>2008-11-06</pubDate>
    <category>Exploits</category>
    <author>Mohanty</author>
    <comments>www.hackingspirits.com</comments>
</item>
<item>
    <title>PHPX 3.5.16 (news_id) Remote SQL Injection Exploit</title>
    <link>http://www.vfocus.net/art/20081106/4100.html</link>
    <description>?php error_reporting(0); ini_set(default_socket_timeout,5); set_time_limit(0); /* --------------------------------------------------- PHP X 3.5.16 (news_id) Remote SQL Injection Exploit --------------------------------------------------- By StAkeR[at</description>
    <pubDate>2008-11-06</pubDate>
    <category>Exploits</category>
    <author>StAkeR</author>
    <comments>StAkeR[at]hotmail[dot]it</comments>
</item>
<item>
    <title>Discuz! 路径信息泄露 bug</title>
    <link>http://www.vfocus.net/art/20081105/4099.html</link>
    <description>Discuz! 路径信息泄露 bugauthor: 80vul-Ateam:http://www.80vul.com一 分析目录uc_clientdatacache,forumdatacache等下面的文件里对如: ___FCKpd___0 CACHE['settings'] = array ( 'accessemail' = '', 'censoremail' = '', 'censorusername' = '', 'dateformat</description>
    <pubDate>2008-11-05</pubDate>
    <category>漏洞资料</category>
    <author>80vul-A</author>
    <comments>www.80vul.com</comments>
</item>
<item>
    <title>Discuz! member.php xss bug</title>
    <link>http://www.vfocus.net/art/20081105/4098.html</link>
    <description>Discuz! member.php xss bugauthor: 80vul-Bteam:http://www.80vul.com一 分析member.php代码:if(!empty($listgid) ($listgid == intval( ___FCKpd___0 GET['listgid']))) {//这里用的等于[==]而不是全等[===]进行的比较,且$listgid并没有初始化:)$type = $adminid ==</description>
    <pubDate>2008-11-05</pubDate>
    <category>漏洞资料</category>
    <author>80vul-B</author>
    <comments>www.80vul.com</comments>
</item>
<item>
    <title>Simple Machines Forum (SMF) 1.1.6 Remote Code Execution Exploit</title>
    <link>http://www.vfocus.net/art/20081105/4097.html</link>
    <description>?php # # Simple Machines Forum (SMF) 1.1.6 Remote Code Execution Exploit # Credits: Charles FOL charlesfol[at]hotmail.fr # URL: http://real.olympe-network.com/ # # Note: other versions are maybe vulnerable, not tested. # # SMF suffers from multiples</description>
    <pubDate>2008-11-05</pubDate>
    <category>Exploits</category>
    <author>Charles</author>
    <comments>charlesfol[at]hotmail.fr</comments>
</item>
<item>
    <title>TR News &lt;= 2.1 (login.php) Remote Login Bypass Exploit</title>
    <link>http://www.vfocus.net/art/20081105/4096.html</link>
    <description>?php error_reporting(0); /* ------------------------------------------------------ TR News = 2.1 (login.php) Remote Login ByPass Exploit ------------------------------------------------------ By StAkeR[at]hotmail[dot]it http://www.easy-script.com/scr</description>
    <pubDate>2008-11-05</pubDate>
    <category>Exploits</category>
    <author>StAkeR</author>
    <comments>StAkeR[at]hotmail[dot]it</comments>
</item>
<item>
    <title>Discuz! admin\runwizard.inc.php get-webshell bug</title>
    <link>http://www.vfocus.net/art/20081104/4095.html</link>
    <description>Discuz! adminrunwizard.inc.php get-webshell bugauthor: 80vul-Ateam:http://www.80vul.com由于Discuz!的adminrunwizard.inc.php里saverunwizardhistory()写文件操作没有限制导致执行代码漏洞.一 分析在文件adminrunwizard.inc.php里代码:$runwizardhistory = arr</description>
    <pubDate>2008-11-04</pubDate>
    <category>漏洞资料</category>
    <author>80vul-A</author>
    <comments>www.80vul.com</comments>
</item>
<item>
    <title>Discuz! modcp/moderate.inc.php 数据库注射bug</title>
    <link>http://www.vfocus.net/art/20081104/4094.html</link>
    <description>Discuz! modcp/moderate.inc.php 数据库注射bugauthor: 80vul-Bteam:http://www.80vul.com一 分析在文件modcpmoderate.inc.php里代码:require_once DISCUZ_ROOT.'./include/discuzcode.func.php';require_once DISCUZ_ROOT.'./include/attachment.func.php';$ppp = 10</description>
    <pubDate>2008-11-04</pubDate>
    <category>漏洞资料</category>
    <author>80vul-B</author>
    <comments>www.80vul.com</comments>
</item>

</channel>
</rss>
