<?xml version="1.0" encoding="ISO-8859-1"?><rss version="2.0"><channel><title>Astalavista.net - Exploits</title><description>Astalavista.net - Advanced Security Memberportal - Exploits</description><link>http://www.astalavista.net</link><webMaster>info@astalavista.net</webMaster><generator>Astalavista.net Memberportal V2</generator><lastBuildDate>Sat, 16 Aug 2008 15:42:59 +0200</lastBuildDate><language>en</language><item><title>Bugzilla 'importxml.pl' with '--attach_path' Option Lets Users Attach Local Files</title><description>Impact:  Disclosure of system information, Disclosure of user information
Fix Available:  Yes   Exploit Included:  Yes ...</description><pubDate>Sat, 16 Aug 2008 15:42:59 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7932</link></item><item><title>xine-lib Bugs in Processing Media Files Lets Remote Users Deny Service and Execute Arbitrary Code</title><description>Impact:  Execution of arbitrary code via network, User access via network
Fix Available:  Yes   Vendor Confirmed:  Yes ...</description><pubDate>Sat, 16 Aug 2008 15:41:09 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7931</link></item><item><title>VitalQIP Query Port Entropy Weakness Lets Remote Users Spoof the System</title><description>Impact:  Modification of system information
Exploit Included:  Yes   Vendor Confirmed:  Yes  
Description:  A vulnerab...</description><pubDate>Sat, 16 Aug 2008 15:40:42 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7930</link></item><item><title>Postfix Symlink Dereference Bug Lets Local Users Gain Elevated Privileges</title><description>Impact:  Root access via local system
Fix Available:  Yes   Vendor Confirmed:  Yes  
Description:  A vulnerability was...</description><pubDate>Sat, 16 Aug 2008 15:40:14 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7929</link></item><item><title>VERITAS Storage Foundation for Windows Accepts NULL NTLMSSP Authentication</title><description>Impact:  Execution of arbitrary code via network, Root access via network
Fix Available:  Yes   Exploit Included:  Yes ...</description><pubDate>Sat, 16 Aug 2008 15:39:36 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7928</link></item><item><title>yum-rhn-plugin Certificate Validation Flaw Lets Remote Users Conduct Man-in-the-Middle Attacks to Pr</title><description>Impact:  Denial of service via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Advisory:  Red Hat Advisory
Des...</description><pubDate>Sat, 16 Aug 2008 15:39:09 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7927</link></item><item><title>Sun Java Web Proxy Server FTP Subsystem Bug Lets Remote Users Deny Service</title><description>Fix Available:  Yes   Vendor Confirmed:  Yes  
Advisory:  Sun Alert
Version(s): 4.0 through 4.0.5
Description:  A vul...</description><pubDate>Sat, 16 Aug 2008 15:38:37 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7926</link></item><item><title>Red Hat Network Satellite Server 'manzier.pxt' Hard Coded Common Authentication Key Lets Remote User</title><description>Impact:  Disclosure of user information
Fix Available:  Yes   Vendor Confirmed:  Yes  
Advisory:  Red Hat Advisory
Ve...</description><pubDate>Sat, 16 Aug 2008 15:38:06 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7925</link></item><item><title>VMware VirtualCenter Discloses Usernames to Remote Users</title><description>Impact:  Disclosure of user information
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): prior to 2.0.2 Upda...</description><pubDate>Sat, 16 Aug 2008 15:37:38 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7924</link></item><item><title>IPsec-Tools Racoon Phase 1 Handle Cleanup Flaw May Let Remote Users Deny Service</title><description>Impact:  Denial of service via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Description:  A vulnerability wa...</description><pubDate>Sat, 16 Aug 2008 15:37:05 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7923</link></item><item><title>Ventrilo &amp;lt;= 3.0.2 NULL pointer Remote DoS Exploit</title><description>NULL pointer in Ventrilo 3.0.2

http://milw0rm.com/sploits/2008-ventrilobotomy.zip
</description><pubDate>Sat, 16 Aug 2008 15:33:07 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7922</link></item><item><title>Ruby &amp;lt;= 1.9 (regex engine) Remote Socket Memory Leak Exploit</title><description>-------------------------------------------------------
Language : Ruby 

Web Site: www.ruby-lang.org

Platform: Al...</description><pubDate>Sat, 16 Aug 2008 15:32:36 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7921</link></item><item><title>FlashGet 1.9 (FTP PWD Response) Remote BOF Exploit PoC 0day</title><description>#!/usr/bin/python
# FlashGet 1.9 (FTP PWD Response) 0day Remote Buffer Overflow PoC Exploit
# Bug discovered by Krysti...</description><pubDate>Sat, 16 Aug 2008 15:32:07 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7920</link></item><item><title>Microsoft Visual Studio (Msmask32.ocx) ActiveX Remote BOF PoC</title><description>var body='&lt;OBJECT CLASSID=&quot;CLSID:C932BA85-4374-101B-A56C-00AA003668DC&quot; 
width=&quot;10&quot;&gt;&lt;PARAM NAME=&quot;Mask&quot; VALUE=&quot;';

var ...</description><pubDate>Sat, 16 Aug 2008 15:31:34 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7919</link></item><item><title>dotCMS 1.6 (id) Multiple Local File Inclusion Vulnerabilities</title><description>++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ script:dotCMS
+ home: http://www.dotcms.org
+ demo: http://w...</description><pubDate>Sat, 16 Aug 2008 15:30:13 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7918</link></item><item><title>ZEEJOBSITE v2.0  (bannerclick.php adid) Remote SQL Injection Vulnerability</title><description>|___________________________________________________|
|
| ZEEJOBSITE v2.0  (bannerclick.php adid) Remote SQL Injection...</description><pubDate>Sat, 16 Aug 2008 15:28:50 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7917</link></item><item><title>DeeEmm CMS (DMCMS) 0.7.4 Multiple Remote Vulnerabilities</title><description>#####################################################################################
####                        DeeEm...</description><pubDate>Sat, 16 Aug 2008 15:28:11 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7916</link></item><item><title>BIND 9.5.0-P2 (randomized ports) Remote DNS Cache Poisoning Exploit</title><description>Successfully poisoned the latest BIND with fully randomized ports!

Exploit required to send more than 130 thousand of...</description><pubDate>Sat, 16 Aug 2008 15:11:18 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7915</link></item><item><title>IntelliTamper 2.07/2.08 Beta 4 A HREF Remote Buffer Overflow Exploit</title><description>/********************************************************************/
/* [Crpt]  IntelliTamper v2.07/2.08 Beta 4 sploi...</description><pubDate>Sat, 16 Aug 2008 15:09:15 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7914</link></item><item><title>FlashGet 1.9.0.1012 (FTP PWD Response) SEH STACK Overflow Exploit</title><description>#!/usr/bin/perl
# FlashGet 1.9.0.1012 (FTP PWD Response) SEH STACK Overflow Exploit
# Coded By SkOd, skod.uk at gmail ...</description><pubDate>Sat, 16 Aug 2008 15:08:41 +0200</pubDate><link>https://www.astalavista.net/member/?cmd=exploit&amp;act=detail&amp;id=7913</link></item></channel></rss>