Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 0.15.x/0.16/0.17.x - JPGraph Remote File Inclusion Command Execution
CVE-2002-1113—webappsphp19 ago 2002
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modify
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kerio MailServer 5.0/5.1 Web Mail - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-1434—webappscgi19 ago 2002
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL 3.20.32/3.22.x/3.23.x - Null Root Password Weak Default Configuration (1)
CVE-2002-1809—remotelinux19 ago 2002
The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lynx 2.8.x - Command Line URL CRLF Injection
CVE-2002-1405—remotelinux19 ago 2002
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4/5/6 - XML Datasource Applet File Disclosure
CVE-2002-0976—localwindows17 ago 2002
Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XM
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SGI IRIX 6.5.x - FAM Arbitrary Root Owned Directory File Listing
CVE-2002-0875—localirix16 ago 2002
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose acces
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 2.0 - Full Path Disclosure
CVE-2002-0654—remotewindows16 ago 2002
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the ser
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Toolbar 1.1.60 - Search Function Denial of Service
CVE-2002-1444—doswindows15 ago 2002
The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of s
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL 2000/7.0 - Agent Jobs Privilege Escalation
CVE-2002-0721—remotewindows15 ago 2002
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP - HCP URI Handler Abuse
CVE-2002-0974—remotewindows15 ago 2002
Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Outlook Express 5/6 - MHTML URL Handler File Rendering
CVE-2002-0980—remotewindows15 ago 2002
The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Leszek Krupinski L-Forum 2.4 - Search Script SQL Injection
CVE-2002-1457—webappsphp14 ago 2002
SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyWebServer 1.0.2 - Long HTTP Request HTML Injection
CVE-2002-1453—remotewindows14 ago 2002
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a lo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyWebServer 1.0.2 - Search Request Remote Buffer Overflow
CVE-2002-1452—remotewindows14 ago 2002
Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a l
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.1 - Arbitrary Command Execution
CVE-2002-1951—remotewindows14 ago 2002
Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat Interchange 4.8.x - Arbitrary File Read
CVE-2002-0874—remotelinux13 ago 2002
Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to rea
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
W3C CERN HTTPd 3.0 Proxy - Cross-Site Scripting
CVE-2002-1445—remoteunix12 ago 2002
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ISDN4Linux 3.1 - IPPPD Device String SysLog Format String (1)
CVE-2002-0851—locallinux10 ago 2002
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Midicart ASP - Remote Customer Information Retrieval
CVE-2002-1432—webappsasp10 ago 2002
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ISDN4Linux 3.1 - IPPPD Device String SysLog Format String (2)
CVE-2002-0851—locallinux10 ago 2002
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 2.0 - Encoded Backslash Directory Traversal
CVE-2002-0661—remotewindows09 ago 2002
Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to r
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Orinoco OEM Residential Gateway - SNMP Community String Remote Configuration
CVE-2002-0812—remotehardware09 ago 2002
Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identif
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BlueFace Falcon Web Server 2.0 - Error Message Cross-Site Scripting
CVE-2002-2318—remotewindows09 ago 2002
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to i
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Qualcomm Eudora 5/6 - File Attachment Spoofing (1)
CVE-2002-2351—remotewindows08 ago 2002
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Qualcomm Eudora 5/6 - File Attachment Spoofing (2)
CVE-2002-2351—remotewindows08 ago 2002
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 / Konqueror 2.2.2/3.0 / Weblogic Server 5/6/7 - Invalid X.509 Certificate Chain
CVE-2002-1183—remotewindows06 ago 2002
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing r
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (7)
CVE-2002-1230—localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (4)
CVE-2002-1230—localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Opera 6.0.x - FTP View Cross-Site Scripting
CVE-2002-2358—remotewindows06 ago 2002
Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 / Konqueror 2.2.2/3.0 / Weblogic Server 5/6/7 - Invalid X.509 Certificate Chain
CVE-2002-0828—remotewindows06 ago 2002
20RIESGO
abrir ↗
← anteriorpágina 568 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.