Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,366cataloged exploits
37,872CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
ttCMS 2.2 / ttForum 1.1 - 'news.php?template' Remote File Inclusion
CVE-2003-1459—webappsphp09 May 2003
Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Lgames LTris 1.0.1 - Local Memory Corruption
CVE-2003-1473—localfreebsd09 May 2003
Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ttCMS 2.2 / ttForum 1.1 - 'install.php?installdir' Remote File Inclusion
CVE-2003-1459—webappsphp09 May 2003
Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Phorum 3.4.x - 'Message Form' HTML Injection
CVE-2003-0283—webappsphp09 May 2003
Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - 'file://' Request Zone Bypass
CVE-2003-0309—remotewindows09 May 2003
Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary
35RISK
open ↗
Exploit-DB✓ VexDay Proof
HappyMall E-Commerce Software 4.3/4.4 - 'Member_HTML.cgi' Command Execution
CVE-2003-0243—webappscgi08 May 2003
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 2.1.4 - Remote Code Execution
CVE-2003-0220—remotewindows08 May 2003
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows r
50RISK
open ↗
Exploit-DB✓ VexDay Proof
ListProc 8.2.9 - Catmail ULISTPROC_UMASK Buffer Overflow
CVE-2003-0274—localfreebsd08 May 2003
Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Media Player 7.1 - Skin File Code Execution
CVE-2003-0228—remotewindows07 May 2003
Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows r
35RISK
open ↗
Exploit-DB✓ VexDay Proof
HappyMall E-Commerce Software 4.3/4.4 - 'Normal_HTML.cgi' Command Execution
CVE-2003-0243—webappscgi07 May 2003
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Leksbot 1.2 - Multiple Vulnerabilities
CVE-2003-0262—locallinux06 May 2003
leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges
23RISK
open ↗
Exploit-DB✓ VexDay Proof
FloosieTek FTGate PRO 1.22 - SMTP RCPT TO Buffer Overflow
CVE-2003-0263—doswindows06 May 2003
Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitr
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Youbin 2.5/3.0/3.4 - 'HOME' Buffer Overflow
CVE-2003-0269—localfreebsd06 May 2003
Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
FloosieTek FTGate PRO 1.22 - SMTP MAIL FROM Buffer Overflow
CVE-2003-0263—doswindows06 May 2003
Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitr
28RISK
open ↗
Exploit-DB✓ VexDay Proof
CommuniGate Pro Webmail 4.0.6 - Session Hijacking
CVE-2003-1481—remotelinux05 May 2003
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allo
23RISK
open ↗
Exploit-DB✓ VexDay Proof
MySQL 3.x/4.0.x - Weak Password Encryption
CVE-2003-1480—locallinux05 May 2003
MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the
23RISK
open ↗
Exploit-DB✓ VexDay Proof
IkonBoard 3.1 - Lang Cookie Arbitrary Command Execution (2)
CVE-2003-0770—webappscgi05 May 2003
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains i
28RISK
open ↗
Exploit-DB✓ VexDay Proof
HP-UX 11 RWrite - Buffer Overflow
CVE-2003-1461—doshp-ux02 May 2003
Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: t
23RISK
open ↗
Exploit-DB✓ VexDay Proof
OpenSSH/PAM 3.6.1p1 - 'gossh.sh' Remote Users Ident
CVE-2003-0190—remotelinux02 May 2003
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RISK
open ↗
Exploit-DB✓ VexDay Proof
KDE Konqueror 3.0.3 - Malformed HTML Page Denial of Service
CVE-2003-1478—doslinux02 May 2003
Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft BizTalk Server 2002 - HTTP Receiver Buffer Overflow
CVE-2003-0117—doswindows30 Apr 2003
Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows att
23RISK
open ↗
Exploit-DB✓ VexDay Proof
OpenSSH/PAM 3.6.1p1 - Remote Users Discovery Tool
CVE-2003-0190—remotelinux30 Apr 2003
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RISK
open ↗
Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 2.1.x - Remote Authentication Packet Buffer Overflow (2)
CVE-2003-0220—remotewindows30 Apr 2003
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows r
50RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft BizTalk Server 2000/2002 DTA - 'RawCustomSearchField.asp' SQL Injection
CVE-2003-0118—webappsasp30 Apr 2003
SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft BizTalk Server 2000/2002 DTA - 'rawdocdata.asp' SQL Injection
CVE-2003-0118—webappsasp30 Apr 2003
SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.12.8 (BSD) - 'Prescan()' Remote Command Execution
CVE-2003-0161—remotelinux30 Apr 2003
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain co
35RISK
open ↗
Exploit-DB✓ VexDay Proof
RealServer < 8.0.2 (Windows Platforms) - Remote Overflow
CVE-2002-1643—remotewindows30 Apr 2003
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbit
60RISK
open ↗
Exploit-DB✓ VexDay Proof
Pi3Web 2.0.1 - Denial of Service (PoC)
CVE-2003-0276—doswindows29 Apr 2003
Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitr
28RISK
open ↗
Exploit-DB✓ VexDay Proof
HP-UX 10.x/11.x - RExec Remote 'Username' Flag Local Buffer Overrun
CVE-2003-1097—doshp-ux29 Apr 2003
Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privile
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Qpopper 4.0.x - 'poppassd' Privilege Escalation
CVE-2003-1452—locallinux29 Apr 2003
Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by
23RISK
open ↗
← previouspage 552 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.