Abysssec

89 exploits Active since Feb 2009
CVE-2010-0519 EXPLOITDB python WORKING POC
Apple Mac OS X - Numeric Error
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.
CVE-2011-0041 EXPLOITDB text WRITEUP
Microsoft GDI+ - RCE
Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."
CVE-2010-0520 EXPLOITDB python WORKING POC
Apple Mac OS X - Memory Corruption
Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI chunks and untrusted length values in a .fli file, which are not properly handled during decompression.
CVE-2010-2866 EXPLOITDB python WORKING POC
Adobe Shockwave Player <11.5.8.612 - Memory Corruption
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a Director movie.
EIP-2026-114605 EXPLOITDB php WORKING POC
ZenPhoto - Config Update / Command Execution
CVE-2009-4089 EXPLOITDB text WRITEUP
telepark.wiki <2.4.23 - Auth Bypass
telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to ajax/deletePage.php or (2) delete arbitrary comments via a modified pageID parameter to ajax/deleteComment.php.
EIP-2026-112526 EXPLOITDB text WORKING POC
SyndeoCMS 2.8.02 - Multiple Vulnerabilities (1)
EIP-2026-111415 EXPLOITDB text WRITEUP
Portili Personal and Team Wiki 1.14 - Multiple Vulnerabilities (2)
EIP-2026-111414 EXPLOITDB text WRITEUP
Portili Personal and Team Wiki 1.14 - Multiple Vulnerabilities (1)
EIP-2026-111158 EXPLOITDB text WORKING POC
phpMyFamily - Multiple Vulnerabilities
CVE-2010-3481 EXPLOITDB text WORKING POC
ApPHP PHP MicroCMS 1.0.1 - SQL Injection
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable.
EIP-2026-107884 EXPLOITDB text WRITEUP
InterPhoto Gallery - Multiple Vulnerabilities
EIP-2026-108075 EXPLOITDB text WORKING POC
JE CMS 1.0.0 - Authentication Bypass
CVE-2010-4893 EXPLOITDB text WRITEUP
FestOS 2.3b - XSS
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary web script or HTML via the category parameter in a details action.
EIP-2026-106609 EXPLOITDB text WRITEUP
dynpage 1.0 - Multiple Vulnerabilities
EIP-2026-106559 EXPLOITDB text WRITEUP
douran portal 3.9.0.23 - Multiple Vulnerabilities
EIP-2026-106221 EXPLOITDB python WRITEUP
Cpanel PHP - Restriction Bypass
EIP-2026-106012 EXPLOITDB html WORKING POC
CMSimple - Cross-Site Request Forgery
EIP-2026-104528 EXPLOITDB python WORKING POC
Novell Netware - NWFTPD RMD/RNFR/DELE Argument Parsing Buffer Overflow
CVE-2010-2168 EXPLOITDB python WORKING POC
Adobe Acrobat - Resource Management Error
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.
EIP-2026-100337 EXPLOITDB text WORKING POC
gausCMS - Multiple Vulnerabilities
EIP-2026-100611 EXPLOITDB html WORKING POC
VWD-CMS - Cross-Site Request Forgery
EIP-2026-100605 EXPLOITDB text WRITEUP
VisualSite CMS 1.3 - Multiple Vulnerabilities
EIP-2026-100604 EXPLOITDB text WRITEUP
visinia 1.3 - Multiple Vulnerabilities
EIP-2026-100547 EXPLOITDB text WORKING POC
sirang web-based d-control - Multiple Vulnerabilities