Waraxe IT Security Portal
Login or Register
August 21, 2026
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 1627
Members: 0
Total: 1627
Full disclosure
[0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8)
[0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8)
[0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8)
[0day-rubbish] RoboTask 11.0.5.1229 Unauthenticated REST API remote task execution (9.8)
[0day-rubbish] ActiveFax Server 10.70 Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (9.8)
[0day-rubbish] Tornado 2.11.3 Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (9.8)
[0day-rubbish] Datalore On-Premises 2026.2.3 Unauthenticated RCE via InteractiveReport access-mapping flaw (9.8)
APPLE-SA-08-18-2026-1 Safari 26.6.1
Cudy WR3000: Hard-coded JWT Secret to Root Command Injection
Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)
Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)
Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology))
Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision)
Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)
Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software)
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index
Search found 10 matches
Smartcard Hex display/reader/writer
PostForum:Newbies corner Posted: Sat Aug 26, 2006 12:54 pm Subject: Smartcard Hex display/reader/writer
piglet
Replies: 0
Views: 7271




Hi,
I'm sorry to post this here but I've searched the net & cannot find anything. Does anyone know of some freeware for XP that will read/write & hex display smart-cards (like the SLE 441 ...
What is Full path disclosure
PostForum:Full path disclosure Posted: Sun Jun 25, 2006 5:58 pm Subject: What is Full path disclosure
piglet
Replies: 3
Views: 16338




I asked this some time ago, is their any tool that produces a table of links within a website? It just goes to the homepage & follows all links. Holes might appear that give insights into possible ...
stopping name & passwords being remembered by browsers.
PostForum:Suggestions Posted: Sun Jun 25, 2006 5:54 pm Subject: stopping name & passwords being remembered by browsers.
piglet
Replies: 3
Views: 12762




I was not aware of this form action. Thanks for the information. Does this ensure that the browser doesn't cache it? I mean, do I have to check non-caching for all browsers & platforms or is it wr ...
stopping name & passwords being remembered by browsers.
PostForum:Suggestions Posted: Sun Jun 25, 2006 9:53 am Subject: stopping name & passwords being remembered by browsers.
piglet
Replies: 3
Views: 12762




Hi,
Almost all sites on the internet which use a name & password field are liable to be remembered by the browser (unless you specify not to). With PHP, it should be possible to generate a di ...
MSSQL now uninjectable?
PostForum:Sql injection Posted: Fri Jan 27, 2006 3:57 pm Subject: MSSQL now uninjectable?
piglet
Replies: 4
Views: 15146




Well, I applied the discound and was told that I owed the grand total of $0.00. Of course, I mailed them and told them about the weakness so that's 1 less hole. Hidden fields for discounts cannot be u ...
MSSQL now uninjectable?
PostForum:Sql injection Posted: Fri Jan 27, 2006 2:49 pm Subject: MSSQL now uninjectable?
piglet
Replies: 4
Views: 15146




I've found the appropriate utility to modify hidden fields with Firefox. A useful user script called 'form help' which allows one to twiddle with all the values in hidden fields. I'm wondering if anyo ...
MSSQL now uninjectable?
PostForum:Sql injection Posted: Thu Jan 26, 2006 3:15 pm Subject: MSSQL now uninjectable?
piglet
Replies: 4
Views: 15146




The only place on the site I can find to inject possibly 'interesting' data is into the order-form in checkout.asp. The form POSTs order details to hidden.asp. There are quite a number of fields. Look ...
MSSQL now uninjectable?
PostForum:Sql injection Posted: Tue Jan 24, 2006 3:56 pm Subject: MSSQL now uninjectable?
piglet
Replies: 4
Views: 15146




I'm also looking into the email addresses connected to the site. Is there any way other than brute-force to get the list of mailboxes connected to a server?
MSSQL now uninjectable?
PostForum:Sql injection Posted: Tue Jan 24, 2006 3:13 pm Subject: MSSQL now uninjectable?
piglet
Replies: 4
Views: 15146




I've been messing with SQL lately & have noticed that all the MSSQL sites seem to have SQL locked down tight. They take only 1 imput field & no outpuf fields. All I can get is.

I put this i ...
Boots.com microsites (JSP)
PostForum:Newbies corner Posted: Tue Jan 17, 2006 2:36 pm Subject: Boots.com microsites (JSP)
piglet
Replies: 0
Views: 7901




Hi,
I've been trying to map out the contents of the boots.com site. Links from their homepage either go to

/shop/category_new_template.jsp?classificationid=xxxxx

one or two are

/shop/pro ...
Page 1 of 1
All times are GMT


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.047 Seconds