[ home ] [ contents ] [ platforms ] [ shellcode ] [ search ] [ cracker ] [ links ] [ rss ] [ archive ]

Author: Stefan Esser <sesser [at] hardened-php.net>
Homepage:http://hardened-php.net


[ exploits/shellcode ]
-::DATE -::DESCRIPTION -::HITS -::AUTHOR
2007-03-27 PHP 4.4.5 / 4.4.6 session_decode() Double Free Exploit PoC 7310 R D Stefan Esser
2007-03-25 PHP < 4.4.5 / 5.2.1 _SESSION unset() Local Exploit 5266 R D Stefan Esser
2007-03-25 PHP < 4.4.5 / 5.2.1 _SESSION Deserialization Overwrite Exploit 5247 R D Stefan Esser
2007-03-23 PHP 5.2.1 unserialize() Local Information Leak Exploit 4528 R D Stefan Esser
2007-03-20 PHP <= 4.4.6 / 5.2.1 ext/gd Already Freed Resources Usage Exploit 4644 R D Stefan Esser
2007-03-20 PHP <= 5.2.1 hash_update_file() Freed Resource Usage Exploit 5495 R D Stefan Esser
2007-03-19 PHP 5.2.0 header() Space Trimming Buffer Underflow Exploit (MacOSX) 4822 R D Stefan Esser
2007-03-16 PHP <= 4.4.6 / 5.2.1 array_user_key_compare() ZVAL dtor Local Exploit 5466 R D Stefan Esser
2007-03-14 PHP <= 5.2.1 session_regenerate_id() Double Free Exploit 3844 R D Stefan Esser
2007-03-14 PHP 5.2.0/5.2.1 Rejected Session ID Double Free Exploit 5301 R D Stefan Esser
2007-03-12 PHP 5.2.0 ext/filter Space Trimming Buffer Underflow Exploit (MacOSX) 4412 R D Stefan Esser
2007-03-10 PHP <= 5.2.0 ext/filter FDF Post Filter Bypass Exploit 7120 R D Stefan Esser
2007-03-09 PHP 5.2.0 / PHP with PECL ZIP <= 1.8.3 zip:// URL Wrapper BoF Exploit 5308 R D Stefan Esser
2007-03-07 PHP <= 5.2.1 substr_compare() Information Leak Exploit 3922 R D Stefan Esser
2007-03-07 mod_security <= 2.1.0 (ASCIIZ byte) POST Rules Bypass Vulnerability 4626 R D Stefan Esser
2007-03-07 PHP < 4.4.5 / 5.2.1 (shmop Functions) Local Code Execution Exploit 4234 R D Stefan Esser
2007-03-07 PHP < 4.4.5 / 5.2.1 (shmop) SSL RSA Private-Key Disclosure Exploit 4167 R D Stefan Esser
2007-03-04 PHP wddx_deserialize() String Append Crash Exploit 2826 R D Stefan Esser
2007-03-04 PHP 4.4.3 - 4.4.6 phpinfo() Remote XSS Vulnerability 12310 R D Stefan Esser
2007-03-04 PHP < 4.4.5 / 5.2.1 php_binary Session Deserialization Information Leak 4627 R D Stefan Esser
2007-03-04 PHP < 4.4.5 / 5.2.1 WDDX Session Deserialization Information Leak 4145 R D Stefan Esser
2007-03-02 PHP <= 4.4.4 unserialize() ZVAL Reference Counter Overflow Exploit PoC 4592 R D Stefan Esser
2007-03-01 PHP 4 Userland ZVAL Reference Counter Overflow Exploit PoC 3652 R D Stefan Esser
2007-01-07 Wordpress 2.0.5 Trackback UTF-7 Remote SQL Injection Exploit 15980 R D Stefan Esser
2005-04-11 PunBB 1.2.4 (change_email) SQL Injection Exploit 8913 R D Stefan Esser



send all submissions to submit[at]milw0rm.com [gpg]

Copyright © 2004-2008 milw0rm