Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
82.322 exploits
Metasploit300
Facebook Photo Uploader 4 ActiveX Control Buffer Overflow
CVE-2008-5711—31 ene 2008
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
webSPELL 4.1.2 - 'whoisonline.php' Cross-Site Scripting
CVE-2008-0574—webappsphp30 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
YeSiL KoRiDoR Ziyaretçi Defteri - 'index.php' SQL Injection
CVE-2008-4611—webappsphp30 ene 2008
SQL injection vulnerability in index.php in PHP Arsivimiz Php Ziyaretci Defteri allows remote attackers to execute arbit
23RIESGO
abrir ↗
Metasploit600
Coppermine Photo Gallery picEditor.php Command Execution
CVE-2008-0506—30 ene 2008
include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AmpJuke 0.7 - 'index.php' Cross-Site Scripting
CVE-2008-0496—webappsphp29 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SunGard Banner Student 7.3 - 'add1' Cross-Site Scripting
CVE-2008-4727—webappsjava29 ene 2008
Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ASPired2Protect Login Page - SQL Injection
CVE-2008-0487—webappsasp28 ene 2008
Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eTicket 1.5.6-RC4 - 'index.php' Cross-Site Scripting
CVE-2008-0552—webappsphp28 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Firebird 2.0.3 Relational Database - 'protocol.cpp' XDR Protocol Remote Memory Corruption
CVE-2008-0387—remotemultiple28 ene 2008
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 m
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mambo Module MOStlyCE 2.4 - 'connector.php' Cross-Site Scripting
CVE-2008-7213—webappsphp28 ene 2008
Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VB Marketing - 'tseekdir.cgi' Local File Inclusion
CVE-2008-0488—webappscgi28 ene 2008
Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ClanSphere 2007.4.4 - 'install.php' Local File Inclusion
CVE-2008-0489—webappsphp28 ene 2008
Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
F5 BIG-IP Application Security Manager 9.4.3 - 'report_type' Cross-Site Scripting
CVE-2008-0539—webappsphp26 ene 2008
Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0738—webappsasp25 ene 2008
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0739—webappsasp25 ene 2008
SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebCalendar 1.1.6 - 'pref.php' Cross-Site Scripting
CVE-2007-6696—webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebCalendar 1.1.6 - 'search.php' Cross-Site Scripting
CVE-2007-6696—webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pre Hotel and Resorts - 'user_login.asp' Multiple SQL Injection Vulnerabilities
CVE-2008-0744—webappsasp25 ene 2008
SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fonality trixbox 2.4.2 - Cross-Site Scripting (1)
CVE-2008-0540—webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Metasploit300
Persits XUpload ActiveX AddFile Buffer Overflow
CVE-2008-0492—25 ene 2008
Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUplo
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fonality trixbox 2.4.2 - Cross-Site Scripting (2)
CVE-2008-0540—webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Metasploit200
Streamcast HTTP User-Agent Buffer Overflow
CVE-2008-0550—24 ene 2008
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iOS Mobile Safari - Memory Exhaustion Remote Denial of Service
CVE-2008-0729—dosios24 ene 2008
Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion an
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.2.5 - cURL 'safe_mode' Security Bypass
CVE-2007-4850—remotephp23 ene 2008
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SDL_image 1.2.6 - Invalid '.GIF' File LWZ Minimum Code Size Remote Buffer Overflow
CVE-2007-6697—doslinux23 ene 2008
Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a de
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Rejetto HTTP File Server (HFS) 1.5/2.x - Multiple Vulnerabilities
CVE-2008-0406—remotewindows23 ene 2008
HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a den
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DeluxeBB 1.1 - 'attachments_header.php' Cross-Site Scripting
CVE-2008-0439—webappsphp22 ene 2008
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novemberborn sIFR 2.0.2/3 - 'txt' Cross-Site Scripting
CVE-2008-0438—remotemultiple22 ene 2008
Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PacerCMS 0.6 - 'id' Multiple SQL Injections
CVE-2008-0451—webappsphp22 ene 2008
Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 2.2.6 mod_negotiation - HTML Injection / HTTP Response Splitting
CVE-2008-0455—remotelinux22 ene 2008
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in th
35RIESGO
abrir ↗
← anteriorpágina 1435 / 2745siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.