Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
CVE-2006-5634webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Spider Friendly Module 1.3.10 - Remote File Inclusion
CVE-2006-5665webappsphp
PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
Free Image Hosting 1.0 - 'forgot_pass.php' File Inclusion
CVE-2006-5670webappsphp
PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
CVE-2006-5672webappsphp
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
CVE-2006-5673webappsphp
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RIESGO
abrir
ReferênciaVexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
CVE-2006-5714remotewindows
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RIESGO
abrir
ReferênciaVexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
CVE-2006-5715remotewindows
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5725remotewindows
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request
23RIESGO
abrir
ReferênciaVexDay Proof
phpDynaSite 3.2.2 - 'racine' Remote File Inclusion
CVE-2006-5760webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Article System 0.6 - 'volume.php' Remote File Inclusion
CVE-2006-5766webappsphp
PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Drake CMS < 0.2.3 ALPHA rev.916 - Remote File Inclusion
CVE-2006-5767webappsphp
PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-5773webappsphp
Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Creasito E-Commerce Content Manager - 'admin' Authentication Bypass
CVE-2006-5777webappsphp
Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged funct
23RIESGO
abrir
ReferênciaVexDay Proof
Omni-NFS Server 5.2 - 'nfsd.exe' Remote Stack Overflow (Metasploit)
CVE-2006-5780remotewindows
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RIESGO
abrir
ReferênciaVexDay Proof
SAP Web Application Server 6.40 - Arbitrary File Disclosure
CVE-2006-5784remotewindows
Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 a
23RIESGO
abrir
ReferênciaVexDay Proof
iPrimal Forums - '/admin/index.php' Change User Password
CVE-2006-5787webappsphp
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwo
23RIESGO
abrir
ReferênciaVexDay Proof
iPrimal Forums - '/admin/index.php' Remote File Inclusion
CVE-2006-5788webappsphp
PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows
23RIESGO
abrir
ReferênciaVexDay Proof
OpenEMR 2.8.1 - 'srcdir' Multiple Remote File Inclusions
CVE-2006-5795webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow
23RIESGO
abrir
ReferênciaVexDay Proof
Soholaunch Pro 4.9 r36 - Remote File Inclusion
CVE-2006-5796webappsphp
Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
CVE-2006-5828webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Quick.CMS.Lite 0.3 - Cookie sLanguage Local File Inclusion
CVE-2006-5834webappsphp
Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include a
23RIESGO
abrir
ReferênciaVexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
CVE-2006-5923webappsphp
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Smiley 1.0 - 'default.asp' Authentication Bypass / SQL Injection
CVE-2006-5952webappsasp
SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Hpecs Shopping Cart - Remote Authentication Bypass
CVE-2006-5962webappsasp
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
CVE-2006-6038webappsphp
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
WORK System E-Commerce 3.0.1 - Remote File Inclusion
CVE-2006-6041webappsphp
Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other ver
23RIESGO
abrir
ReferênciaVexDay Proof
PHPWebThings 1.5.2 - 'editor.php' Remote File Inclusion
CVE-2006-6042webappsphp
PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is e
23RIESGO
abrir
ReferênciaVexDay Proof
Etomite CMS 0.6.1.2 - '/manager/index.php' Local File Inclusion
CVE-2006-6047webappsphp
Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component MosReporter 0.9.3 - Remote File Inclusion
CVE-2006-6051webappsphp
PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and
23RIESGO
abrir
ReferênciaVexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
CVE-2006-6063localwindows
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RIESGO
abrir
anteriorpágina 187 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.