Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.250exploits catalogados
37.815CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Apache Tomcat 3.2.3/3.2.4 - 'Source.jsp' Information Disclosure
CVE-2002-2007—remotemultiple29 may 2002
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system informatio
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netscape Enterprise Web Server for Netware 4/5 5.0 - Information Disclosure
CVE-2002-1634—remotenovell29 may 2002
Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndso
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Image Display System 0.8.1 - Directory Existence Disclosure
CVE-2002-1837—webappscgi28 may 2002
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.0 - Call Center Buffer Overflow
CVE-2002-0031—remotewindows27 may 2002
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsg
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Opera 6.0.1/6.0.2 - Arbitrary File Disclosure
CVE-2002-0898—remotewindows27 may 2002
Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows 95/98/2000/NT 4.0 - WinHlp Item Buffer Overflow
CVE-2002-0823—remotewindows27 may 2002
Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HT
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPBB2 - Image Tag HTML Injection
CVE-2002-0902—webappsphp26 may 2002
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenBB 1.0.0 RC3 - BBCode Cross Agent HTML Injection
CVE-2002-0330—webappsphp24 may 2002
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to exe
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft MSN Messenger 1 < 4 - Malformed Invite Request Denial of Service
CVE-2002-1831—doswindows24 may 2002
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.9.x/8.10.x/8.11.x/8.12.x - File Locking Denial of Service (1)
CVE-2002-1827—doslinux24 may 2002
Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.9.x/8.10.x/8.11.x/8.12.x - File Locking Denial of Service (2)
CVE-2002-1827—doslinux24 may 2002
Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MIT PGP Public Key Server 0.9.2/0.9.4 - Search String Remote Buffer Overflow
CVE-2002-0900—doslinux24 may 2002
Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (cras
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenBB 1.0 - Unauthorized Moderator Access
CVE-2002-1830—webappsphp24 may 2002
Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenBB 1.0.0 RC3 - BBCode Cross Agent HTML Injection
CVE-2002-1829—webappsphp24 may 2002
Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ViewCVS 0.9.2 - Cross-Site Scripting
CVE-2002-0771—webappscgi24 may 2002
Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LocalWEB2000 2.1.0 Standard - File Disclosure
CVE-2002-0897—remotewindows24 may 2002
LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco CBOS 2.x - Broadband Operating System TCP/IP Stack Denial of Service
CVE-2002-0886—doshardware23 may 2002
Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memor
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NewAtlanta ServletExec/ISAPI 4.1 - Full Path Disclosure
CVE-2002-0892—remotewindows22 may 2002
The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web r
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NewAtlanta ServletExec/ISAPI 4.1 JSPServlet - Denial of Service
CVE-2002-0894—doswindows22 may 2002
NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a lo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Matu FTP Server 1.13 - Remote Buffer Overflow
CVE-2002-0895—remotewindows22 may 2002
Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NewAtlanta ServletExec/ISAPI 4.1 - File Disclosure
CVE-2002-0893—remotewindows22 may 2002
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.0 - ICMP Redirect Denial of Service
CVE-2002-2315—doshardware21 may 2002
Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a deni
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Youngzsoft CMailServer 3.30/4.0 - Remote Buffer Overflow (2)
CVE-2002-0799—remotewindows21 may 2002
Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argumen
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Youngzsoft CMailServer 3.30/4.0 - Remote Buffer Overflow (1)
CVE-2002-0799—remotewindows20 may 2002
Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argumen
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNU Mailman 2.0.x - Admin Login Cross-Site Scripting
CVE-2002-0388—webappscgi20 may 2002
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
psyBNC 2.3 - Denial of Service
CVE-2002-0741—dosmultiple19 may 2002
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a P
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hosting Controller 1.x - 'Browse.asp' File Disclosure
CVE-2002-0775—webappsasp19 may 2002
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco IDS Device Manager 3.1.1 - Arbitrary File Read Access
CVE-2002-0908—remotehardware17 may 2002
Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Phorum 3.3.2a - Remote Command Execution
CVE-2002-0764—webappsphp17 may 2002
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Grsecurity Kernel Patch 1.9.4 (Linux Kernel) - Memory Protection
CVE-2002-1826—locallinux17 may 2002
grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly ma
23RIESGO
abrir ↗
← anteriorpágina 575 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.