Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
tinyserver 1.1 - Directory Traversal
CVE-2004-2116—remotewindows24 ene 2004
Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Netware Enterprise Web Server 5.1/6.0 - env.bas Information Disclosure
CVE-2004-2104—remotenetware23 ene 2004
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, includi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Reptile Web Server Reptile Web Server 20020105 - Denial of Service
CVE-2004-2120—dosmultiple23 ene 2004
Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET re
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Netware Enterprise Web Server 5.1/6.0 SnoopServlet - Information Disclosure
CVE-2004-2104—remotenetware23 ene 2004
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, includi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Netware Enterprise Web Server 5.1/6.0 - snoop.jsp Information Disclosure
CVE-2004-2104—remotenetware23 ene 2004
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, includi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Finjan SurfinGate 6.0/7.0 - FHTTP Restart Command Execution
CVE-2004-2107—remotelinux23 ene 2004
Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Need for Speed 2 - Remote Client Buffer Overflow (PoC)
CVE-2004-2099—doswindows23 ene 2004
Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (ser
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Acme thttpd 1.9/2.0.x - CGI Test Script Cross-Site Scripting
CVE-2004-2102—remotecgi22 ene 2004
Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to injec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
McAfee ePolicy Orchestrator 1.x/2.x/3.0 Agent - POST Buffer Mismanagement
CVE-2004-0095—doswindows22 ene 2004
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) an
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mephistoles HTTPd 0.6 - Cross-Site Scripting
CVE-2004-2096—remotemultiple21 ene 2004
Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Darkwet Network WebcamXP 1.6.945 - Cross-Site Scripting
CVE-2004-2094—remotemultiple21 ene 2004
Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebTrends Reporting Center 6.1 Management Interface - Full Path Disclosure
CVE-2004-2748—remotewindows20 ene 2004
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the insta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Leif M. Wright Web Blog 1.1 - File Disclosure
CVE-2004-2127—webappscgi20 ene 2004
Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
2WIRE HomePortal Series - Directory Traversal
CVE-2004-2749—remotewindows20 ene 2004
Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other prod
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
anteco visual technologies ownserver 1.0 - Directory Traversal
CVE-2004-2745—remotewindows20 ene 2004
Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to rea
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
YABB SE 1.x - 'SSI.php' ID_MEMBER SQL Injection
CVE-2004-2754—webappsphp19 ene 2004
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.x - 'Descendancy.php' Cross-Site Scripting
CVE-2004-0067—webappsphp19 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XtremeASP PhotoGallery 2.0 - 'Adminlogin.asp' SQL Injection
CVE-2004-2746—webappsasp16 ene 2004
SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SuSE Linux 9.0 - YaST Configuration Skribt Overwrite Files
CVE-2004-0064—locallinux15 ene 2004
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlin
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.23/2.6.0 - 'do_mremap()' Bound Checking Privilege Escalation
CVE-2003-0985—locallinux15 ene 2004
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
lftp 2.6.9 - Remote Stack Overflow
CVE-2003-0963—remotelinux14 ene 2004
Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers t
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KAME Racoon - 'Initial Contact' SA Deletion
CVE-2004-0164—dosfreebsd14 ene 2004
KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Individual.php' Cross-Site Scripting
CVE-2004-0067—webappsphp12 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'login.php' Newlanguage Cross-Site Scripting
CVE-2004-0067—webappsphp12 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Gedrecord.php' Cross-Site Scripting
CVE-2004-0067—webappsphp12 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HD Soft Windows FTP Server 1.5/1.6 - 'Username' Format String
CVE-2004-0069—remotewindows12 ene 2004
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'login.php?Username' Cross-Site Scripting
CVE-2004-0067—webappsphp12 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Placelist.php' SQL Injection
CVE-2004-0067—webappsphp12 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Source.php' Cross-Site Scripting
CVE-2004-0067—webappsphp12 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Imageview.php' Cross-Site Scripting
CVE-2004-0067—webappsphp12 ene 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
← anteriorpágina 537 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.