<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
    <title>ExploitAlert Database - Exploit Database</title>
    <link>http://securityreason.com/exploit_alert</link>
    <description>ExploitAlert Database monitors new exploits and helps you to keep track of the latest exploits, 0days, proof of concepts.</description>
    <language>en-us</language>
    <copyright>Copyright © SecurityReason. All Rights Reserved.</copyright>
    <lastBuildDate>Sun, 21 Mar 2010 03:23:18 +0100</lastBuildDate>
	<image>
      <title>ExploitAlert Database - Exploit Database</title>
      <link>http://securityreason.com/exploit_alert</link>
      <url>http://securityreason.com/gfx/logo.gif</url>
	  <height>70</height>
	  <width>144</width>
	  <description>ExploitAlert Database - SecurityReason.com</description>
    </image>
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/exploit_database" /><feedburner:info uri="exploit_database" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>exploit_database</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/exploit_database" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2Fexploit_database" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
	<title>Httpdx v1.5.3b Remote Crash Service (if http.log=1) PoC</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/xXwesYpEMMw/8001</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/8001</guid>
	  <pubDate>Fri, 19 Mar 2010 20:30:12 +0100</pubDate>
	  <description>Program          : Httpdx v1.5.3b&lt;br /&gt;
PoC              : Remote Crash Service (if http.log=1)&lt;br /&gt;
Homepage         : http://sourceforge.net/projects/httpdx/&lt;br /&gt;
Found by         : Jonathan Salwan&lt;br /&gt;
This Advisory    : Jonathan Salwan&lt;br /&gt;
Contact          : j.salwan@sysdream.com&lt;br /&gt;
&lt;br /&gt;
//----- Application description&lt;br /&gt;
 &lt;br /&gt;
Single-process HTTP1.1/FTP server; no threads or processes started per&lt;br /&gt;
connection, runs with only few threads. Includes directory listi&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/QUxKb2sk1gUheZCvUTjSNXBN4Fk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QUxKb2sk1gUheZCvUTjSNXBN4Fk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/QUxKb2sk1gUheZCvUTjSNXBN4Fk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QUxKb2sk1gUheZCvUTjSNXBN4Fk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/xXwesYpEMMw" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/8001</feedburner:origLink></item>
		<item>
	<title>IBM Lotus 6.x HTTP Response Splitting Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/iu3ZxvOEh6k/8000</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/8000</guid>
	  <pubDate>Fri, 19 Mar 2010 20:28:31 +0100</pubDate>
	  <description>=========================================&lt;br /&gt;
Yaniv Miron aka &amp;quot;Lament&amp;quot; Advisory March 12, 2010&lt;br /&gt;
IBM Lotus 6.x HTTP Response Splitting Vulnerability&lt;br /&gt;
=========================================&lt;br /&gt;
&lt;br /&gt;
=====================&lt;br /&gt;
I. BACKGROUND&lt;br /&gt;
=====================&lt;br /&gt;
&lt;br /&gt;
IBM Lotus Software delivers robust collaboration software that empowers&lt;br /&gt;
people to connect, collaborate, and innovate while optimizing the way they&lt;br /&gt;
work. With Lotus you &lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZyUQCIs5gTheOCUAVo0Ya_TrLkQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZyUQCIs5gTheOCUAVo0Ya_TrLkQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZyUQCIs5gTheOCUAVo0Ya_TrLkQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZyUQCIs5gTheOCUAVo0Ya_TrLkQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/iu3ZxvOEh6k" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/8000</feedburner:origLink></item>
		<item>
	<title>Manage Engine Service Desk Plus 7.6 woID SQL Injection Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/hH4aH6TMsTk/7999</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7999</guid>
	  <pubDate>Fri, 19 Mar 2010 20:27:59 +0100</pubDate>
	  <description>Advisory Name: SQL injection in Manage Engine Service Desk Plus 7.6&lt;br /&gt;
Vulnerability Class: SQL injection&lt;br /&gt;
Release Date: 03-18-2010&lt;br /&gt;
Affected Applications: Confirmed in version 7.6. Other versions may also be&lt;br /&gt;
affected.&lt;br /&gt;
Affected Platforms: Multiple&lt;br /&gt;
Local / Remote: Remote&lt;br /&gt;
Severity: High &amp;amp;#8211; CVSS: 9 (AV:N/AC:L/Au:S/C:C/I:C/A:C)&lt;br /&gt;
Researcher: Nahuel Grisolía&lt;br /&gt;
Vendor Status: Acknowledged. Not fixed.&lt;br /&gt;
Vulnerability Description:&lt;br /&gt;
&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/hN5xTiXla4pV2weBOGe1lhGxA40/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hN5xTiXla4pV2weBOGe1lhGxA40/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/hN5xTiXla4pV2weBOGe1lhGxA40/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hN5xTiXla4pV2weBOGe1lhGxA40/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/hH4aH6TMsTk" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7999</feedburner:origLink></item>
		<item>
	<title>Shutter 0.1.4 Blind SQL Injection Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/YQH3SW2-QI4/7998</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7998</guid>
	  <pubDate>Fri, 19 Mar 2010 20:24:56 +0100</pubDate>
	  <description>&lt;br /&gt;
view source&lt;br /&gt;
print?&lt;br /&gt;
# Exploit Title: Shutter 0.1.4 Blind SQL Injection&lt;br /&gt;
# Date: March 18, 2010&lt;br /&gt;
# Author: Blake&lt;br /&gt;
# Software Link:&lt;br /&gt;
http://sourceforge.net/projects/shutter-php/files/shutter/v0.1.4/shutter_0.&lt;br /&gt;
1.4.zip/download&lt;br /&gt;
# Version: version 0.1.4&lt;br /&gt;
 &lt;br /&gt;
The albumID and photoID parameters are vulnerable to SQL Injection.&lt;br /&gt;
 &lt;br /&gt;
POC:&lt;br /&gt;
http://server/shutter/admin.html?albumID=2%20and%20substring%28@@version,1,&lt;br /&gt;
&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6D971p64eyL7DjlhpZngUb49Aoo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6D971p64eyL7DjlhpZngUb49Aoo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6D971p64eyL7DjlhpZngUb49Aoo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6D971p64eyL7DjlhpZngUb49Aoo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/YQH3SW2-QI4" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7998</feedburner:origLink></item>
		<item>
	<title>SiteDone Custom Edition 2.0 SQL Injection &amp; XSS Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/oAIxG1naQco/7997</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7997</guid>
	  <pubDate>Fri, 19 Mar 2010 20:24:13 +0100</pubDate>
	  <description>[~] SiteDone Custom Edition 2.0 SQL Injection &amp;amp; XSS Vulnerability&lt;br /&gt;
[~]&lt;br /&gt;
[~] http://www.sitedone.com&lt;br /&gt;
[~]&lt;br /&gt;
[~]&lt;br /&gt;
[~]&lt;br /&gt;
---------------------------------------------------------------------------&lt;br /&gt;
--------------------&lt;br /&gt;
[~] Bug founded by d3v1l [Avram Marius]&lt;br /&gt;
[~]&lt;br /&gt;
[~] Date: 18.03.2010&lt;br /&gt;
[~]&lt;br /&gt;
[~]&lt;br /&gt;
[~] http://security-sh3ll.blogspot.com&lt;br /&gt;
[~]&lt;br /&gt;
[~]&lt;br /&gt;
------------------------------------------------------------&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/rhZrsLZ0LlhOPiCmz3wjC8TLCRw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rhZrsLZ0LlhOPiCmz3wjC8TLCRw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/rhZrsLZ0LlhOPiCmz3wjC8TLCRw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rhZrsLZ0LlhOPiCmz3wjC8TLCRw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/oAIxG1naQco" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7997</feedburner:origLink></item>
		<item>
	<title>Quality Point 1.0 NewsFeed (SQL/XSS) Multiple Remote Vulnerabilities</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/HjDFlA0Rw-k/7996</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7996</guid>
	  <pubDate>Fri, 19 Mar 2010 20:23:03 +0100</pubDate>
	  <description>sEc-r1z crEw The Leaders for Penetration Testing In Middle East.&lt;br /&gt;
+==========================================================================&lt;br /&gt;
=========+&lt;br /&gt;
            ./SEC-R1Z   _ __ _  _ _ _ ___ _ _ _ _   __  _ _ _ _ _         &lt;br /&gt;
            / /_ _ _ _ /   _ _\/   _ _ /\        \&amp;lt;   |/_ _ _ _ /&lt;br /&gt;
            \ \_ _ _ _/  /___ /  /   __  |  |)   / |  |   /   /&lt;br /&gt;
             \_ _ _ _/  /___ /  /  | __ ||      /  |  |  /   /&lt;br /&gt;
              _______\  \_ _ &lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/86h69ds__HtccbAHbgDG5MOOQKk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/86h69ds__HtccbAHbgDG5MOOQKk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/86h69ds__HtccbAHbgDG5MOOQKk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/86h69ds__HtccbAHbgDG5MOOQKk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/HjDFlA0Rw-k" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7996</feedburner:origLink></item>
		</channel>
</rss>
