Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
GoAhead Web Server 2.1.x - '.ASP' File Source Code Disclosure
CVE-2002-1603remotewindows17 dic 2002
GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated
28RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 3.23.x/4.0.x - 'COM_CHANGE_USER' Password Length Account
CVE-2002-1374remoteunix16 dic 2002
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privilege
28RIESGO
abrir
Exploit-DBVexDay Proof
MyPHPSoft MyPHPLinks 2.1.9/2.2 - SQL Injection Administration Bypassing
CVE-2002-2304webappsphp14 dic 2002
SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Site Server 4.0.11 - 'PHPInfo.php' Information Disclosure
CVE-2002-2247webappsphp12 dic 2002
The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Site Server 4.0.11 - Full Path Disclosure
CVE-2002-2288webappsphp12 dic 2002
Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.
23RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 3.23.x/4.0.x - COM_CHANGE_USER Password Memory Corruption
CVE-2002-1375remoteunix12 dic 2002
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary
28RIESGO
abrir
Exploit-DBVexDay Proof
Deerfield VisNetic WebSite 3.5.13.1 - Cross-Site Scripting
CVE-2002-2246webappsphp12 dic 2002
Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DBVexDay Proof
HP-UX 11 - Software Distributor Lang Environment Variable Local Buffer Overrun
CVE-2003-0089localhp-ux11 dic 2002
Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
HP-UX 11.0/11.11 - 'swxxx' Privilege Escalation
CVE-2001-0979localhp-ux11 dic 2002
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro PC-cillin 2000/2002/2003 - Mail Scanner Buffer Overflow
CVE-2002-1349remotewindows10 dic 2002
Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a lo
23RIESGO
abrir
Exploit-DBVexDay Proof
Mollensoft Software Enceladus Server Suite 3.9 - 'FTP' Buffer Overflow
CVE-2002-2232doswindows09 dic 2002
Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) comm
23RIESGO
abrir
Exploit-DBVexDay Proof
Cobalt RaQ4 - Administrative Interface Command Execution
CVE-2002-1361remotelinux05 dic 2002
overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to
28RIESGO
abrir
Exploit-DBVexDay Proof
Exim Internet Mailer 3.35/3.36/4.10 - Format String
CVE-2002-1381locallinux04 dic 2002
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative user
23RIESGO
abrir
Exploit-DBVexDay Proof
SAP DB 7.3.00 - Symbolic Link
CVE-2002-1576localunix04 dic 2002
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which a
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache 1.3.x + Tomcat 4.0.x/4.1.x mod_jk - Chunked Encoding Denial of Service
CVE-2002-2272dosunix04 dic 2002
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a de
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.3 - 'search.php' Cross-Site Scripting
CVE-2002-2255webappsphp03 dic 2002
Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
Cyrus IMAPD 1.4/1.5.19/2.0.12/2.0.16/2.1.9/2.1.10 - Pre-Login Heap Corruption
CVE-2002-1580doslinux02 dic 2002
Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code v
28RIESGO
abrir
Exploit-DBVexDay Proof
3Com SuperStack 3 NBX 4.0/4.1 - FTPD Denial of Service
CVE-2002-2300doshardware02 dic 2002
Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial
23RIESGO
abrir
Exploit-DBVexDay Proof
Pserv 2.0 - HTTP Version Specifier Buffer Overflow
CVE-2002-2295doslinux30 nov 2002
Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (c
23RIESGO
abrir
Exploit-DBVexDay Proof
Moby NetSuite 1.0/1.2 - POST Handler Buffer Overflow
CVE-2002-2258dosmultiple29 nov 2002
Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large int
23RIESGO
abrir
Exploit-DBVexDay Proof
YaBB 1 Gold SP 1 - 'YaBB.pl' Cross-Site Scripting
CVE-2002-2296webappscgi28 nov 2002
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Lib CGI 0.1 - Include Buffer Overflow
CVE-2002-2251remoteunix27 nov 2002
Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
BizDesign ImageFolio 2.x/3.0.1 - 'imageFolio.cgi?direct' Cross-Site Scripting
CVE-2002-1334webappscgi27 nov 2002
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
BizDesign ImageFolio 2.x/3.0.1 - 'nph-build.cgi' Cross-Site Scripting
CVE-2002-1334webappscgi27 nov 2002
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
News Evolution 1.0/2.0 - Include Undefined Variable Command Execution
CVE-2002-2249webappsphp26 nov 2002
PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands
23RIESGO
abrir
Exploit-DBVexDay Proof
acFTP 1.4 - Invalid Password Weak Authentication
CVE-2002-2417remotewindows25 nov 2002
acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 2.0.x/2.2.x - 'members2.php' Cross-Site Scripting
CVE-2002-2235webappsphp25 nov 2002
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which caus
23RIESGO
abrir
Exploit-DBVexDay Proof
XFree86 X11R6 3.3.x - Font Server Remote Buffer Overrun
CVE-2002-1317remoteunix25 nov 2002
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers t
28RIESGO
abrir
Exploit-DBVexDay Proof
Zeroo HTTP Server 1.5 - Directory Traversal (1)
CVE-2002-2416remotelinux22 nov 2002
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 2.0/2.2.x - 'memberlist.php' Cross-Site Scripting
CVE-2004-1824webappsphp22 nov 2002
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web
23RIESGO
abrir
anteriorpágina 560 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.