Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
Cisco IDS Device Manager 3.1.1 - Arbitrary File Read Access
CVE-2002-0908—remotehardware17 May 2002
Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Hosting Controller 1.4 - Import Root Directory Command Execution
CVE-2002-0773—webappsasp17 May 2002
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a d
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Hosting Controller 1.x - DSNManager Directory Traversal
CVE-2002-0772—webappsasp17 May 2002
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary fil
23RISK
open ↗
Exploit-DB✓ VexDay Proof
id Software Quake II Server 3.20/3.21 - Remote Information Disclosure
CVE-2002-0770—remotemultiple15 May 2002
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory li
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Content-Disposition Handling File Execution
CVE-2002-0193—remotewindows15 May 2002
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposit
35RISK
open ↗
Exploit-DB✓ VexDay Proof
Opera 5.12/6.0 - Frame Location Same Origin Policy Circumvention
CVE-2002-0783—remotewindows15 May 2002
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Content-Disposition Handling File Execution
CVE-2002-0192—remotewindows15 May 2002
20RISK
open ↗
Exploit-DB✓ VexDay Proof
Squid 2.4.1 - Remote Buffer Overflow
CVE-2002-0163—remotelinux14 May 2002
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows
28RISK
open ↗
Exploit-DB✓ VexDay Proof
NOCC 0.9.x - Webmail Script Injection
CVE-2002-2343—webappsphp14 May 2002
Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web scrip
23RISK
open ↗
Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.1 - Remote Command Execution
CVE-2001-0550—remotelinux14 May 2002
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which i
45RISK
open ↗
Exploit-DB✓ VexDay Proof
Critical Path InJoin Directory Server 4.0 - File Disclosure
CVE-2002-0786—remotemultiple10 May 2002
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators
23RISK
open ↗
Exploit-DB✓ VexDay Proof
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)
CVE-2002-0379—remotelinux10 May 2002
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Critical Path InJoin Directory Server 4.0 - Cross-Site Scripting
CVE-2002-0787—remotemultiple10 May 2002
Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 all
23RISK
open ↗
Exploit-DB✓ VexDay Proof
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (2)
CVE-2002-0379—remotelinux10 May 2002
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Cisco ATA-186 - HTTP Device Configuration Disclosure
CVE-2002-0769—remotehardware09 May 2002
The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ISC DHCPD 2.0/3.0.1 - NSUPDATE Remote Format String
CVE-2002-0702—remotebsd08 May 2002
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0
35RISK
open ↗
Exploit-DB✓ VexDay Proof
WorldClient 5.0.x - Arbitrary File Deletion
CVE-2002-1741—remotewindows07 May 2002
Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
MDaemon WorldClient 5.0.x - Folder Creation Buffer Overflow
CVE-2002-1740—remotewindows07 May 2002
Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users t
23RISK
open ↗
Exploit-DB✓ VexDay Proof
B2 0.6 - 'b2edit.showposts.php?b2inc' Remote File Inclusion
CVE-2002-0734—webappsphp06 May 2002
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, wh
23RISK
open ↗
Exploit-DB✓ VexDay Proof
askSam 4.0 Web Publisher - Cross-Site Scripting
CVE-2002-1727—webappscgi05 May 2002
Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows re
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Outfront Spooky 2.x - Login SQL Query Manipulation Password
CVE-2002-1720—webappsasp02 May 2002
SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain pr
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SSH (x2) - Remote Command Execution
CVE-2001-0144—remotemultiple01 May 2002
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server
35RISK
open ↗
Exploit-DB✓ VexDay Proof
MyGuestbook 1.0 - Script Injection
CVE-2002-0732—webappscgi30 Apr 2002
Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML
23RISK
open ↗
Exploit-DB✓ VexDay Proof
BEA Systems WebLogic Server and Express 7.0 - Null Character Denial of Service
CVE-2002-0106—doswindows30 Apr 2002
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP fi
23RISK
open ↗
Exploit-DB✓ VexDay Proof
DNSTools 2.0 - Authentication Bypass
CVE-2002-0613—webappsphp28 Apr 2002
dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Blahz-DNS 0.2 - Direct Script Call Authentication Bypass
CVE-2002-0599—webappsphp28 Apr 2002
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesti
28RISK
open ↗
Exploit-DB✓ VexDay Proof
ACME Labs thttpd 2.20 - Cross-Site Scripting
CVE-2002-0733—remotelinux25 Apr 2002
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
PHProjekt 2.x/3.x - Authentication Bypass
CVE-2002-1757—webappsphp25 Apr 2002
PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (4)
CVE-2002-0079—remotewindows24 Apr 2002
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache Tomcat 4.0/4.1 - Servlet Full Path Disclosure
CVE-2002-2006—remoteunix23 Apr 2002
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the in
35RISK
open ↗
← previouspage 576 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.