Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
NullLogic Null HTTPd 0.5 - Error Page Cross-Site Scripting
CVE-2002-1497—remotemultiple02 sep 2002
Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FactoSystem Weblog 0.9/1.0/1.1 - Multiple SQL Injections
CVE-2002-1499—webappsasp31 ago 2002
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actio
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP-UX LPD 10.20/11.00/11.11 - Command Execution (Metasploit)
CVE-2002-1473—remotehp-ux28 ago 2002
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of ser
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (1)
CVE-2002-1506—locallinux28 ago 2002
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG enviro
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (2)
CVE-2002-1506—locallinux28 ago 2002
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG enviro
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Webmin 0.x - 'RPC' Privilege Escalation
CVE-2002-2360—remotelinux28 ago 2002
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (3)
CVE-2002-1506—locallinux28 ago 2002
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG enviro
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Caldera X Server 7.1/8.0 - External Program Privileged Invocation
CVE-2002-0987—localunix27 ago 2002
X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp us
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
mIRC 6.0 - Scripting ASCTime Buffer Overflow
CVE-2002-1456—remotewindows27 ago 2002
Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OmniHTTPd 1.1/2.0.x/2.4 - 'test.php' Sample Application Cross-Site Scripting
CVE-2002-1455—remotewindows26 ago 2002
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into we
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OmniHTTPd 1.1/2.0.x/2.4 - test.shtml Sample Application Cross-Site Scripting
CVE-2002-1455—remotewindows26 ago 2002
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into we
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Word 95/97/98/2000/2002 / Excel 2002 - INCLUDETEXT Document Sharing File Disclosure
CVE-2002-1143—remotewindows26 ago 2002
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the i
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Belkin F5D6130 Wireless Network Access Point - SNMP Request Denial of Service
CVE-2002-1811—doshardware26 ago 2002
Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of servic
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Blazix 1.2 - Password Protected Directory Information Disclosure
CVE-2002-1451—remotemultiple25 ago 2002
Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPReactor 1.2.7 - Style Attribute HTML Injection
CVE-2002-2424—webappsphp24 ago 2002
Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GDAM123 0.933/0.942 - Filename Buffer Overflow
CVE-2002-1812—localunix24 ago 2002
Buffer overflow in gdam123 0.933 and 0.942 allows local users to execute arbitrary code via a long filename parameter.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Blazix 1.2 - Special Character Handling Server Side Script Information Disclosure
CVE-2002-1451—remotemultiple24 ago 2002
Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - XML Redirect File Disclosure
CVE-2002-0648—remotewindows23 ago 2002
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attac
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Abyss Web Server 1.0 - Encoded Backslash Directory Traversal
CVE-2002-1079—remotewindows22 ago 2002
Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Achievo 0.7/0.8/0.9 - Remote File Inclusion / Command Execution
CVE-2002-1435—webappsphp22 ago 2002
class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Network Share Provider SMB Request Buffer Overflow (2)
CVE-2002-0724—doswindows22 ago 2002
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows atta
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Network Share Provider SMB Request Buffer Overflow (1)
CVE-2002-0724—doswindows22 ago 2002
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows atta
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 Legacy Text Formatting - ActiveX Component Buffer Overflow
CVE-2002-0647—remotewindows22 ago 2002
Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Tomcat 4.1 - JSP Request Cross-Site Scripting
CVE-2002-1567—remoteunix21 ago 2002
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script an
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Bonsai - Multiple Cross-Site Scripting Vulnerabilities
CVE-2003-0154—webappscgi20 ago 2002
Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell NetWare 5.1/6.0 - POST Arbitrary Perl Code Execution
CVE-2002-1436—remotenovell20 ago 2002
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl cod
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SCPOnly 2.3/2.4 - SSH Environment Shell Escaping
CVE-2002-1469—locallinux20 ago 2002
scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Bonsai 1.3 - Full Path Disclosure
CVE-2003-0153—webappscgi20 ago 2002
bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Disclosure
CVE-2002-1423—webappsphp19 ago 2002
tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the fi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Modification
CVE-2002-1422—webappsphp19 ago 2002
admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in th
23RIESGO
abrir ↗
← anteriorpágina 567 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.