Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Wired Community Software WWWThreads 5.0 - SQL Command Input
CVE-2000-0125—remotecgi03 feb 2000
wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 - Directory Traversal (MS00-006)
CVE-2000-0126—remotemultiple02 feb 2000
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
QuickCommerce 2.5/3.0 / Cart32 2.5 a/3.0 / Shop Express 1.0 / StoreCreator 3.0 Web Shopping Cart - Hidden Form Field
CVE-2000-0136—remotecgi01 feb 2000
The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - Recycle Bin Pre-created Folder
CVE-2000-0121—localwindows01 feb 2000
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Debian 2.1 - apcd Symlink
CVE-2000-0107—locallinux01 feb 2000
Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Outlook Express 5 - JavaScript Email Access
CVE-2000-0105—remotewindows01 feb 2000
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Outlook Express 5 - JavaScript Email Access
CVE-2000-0653—remotewindows01 feb 2000
Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
H. Nomura Tiny FTPDaemon 0.52 - Multiple Buffer Overflow Vulnerabilities
CVE-2000-0133—remotewindows01 feb 2000
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Virtual Machine 2000 - Series/3000 Series getSystemResource
CVE-2000-0132—remotewindows31 ene 2000
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Check Point Software Firewall-1 3.0 Script - Tag Checking Bypass
CVE-2000-0116—remotemultiple29 ene 2000
Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restric
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - Directory Traversal
CVE-2000-0097—remotewindows26 ene 2000
The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed H
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Inter7 vpopmail (vchkpw) 3.4.11 - Local Buffer Overflow
CVE-2000-0091—locallinux21 ene 2000
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 3.4 / NetBSD 1.4.1 / OpenBSD 2.6 - '/proc' FileSystem
CVE-2000-0094—localbsd21 ene 2000
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PowerScripts PlusMail WebConsole 1.0 - Weak Authentication (3)
CVE-2000-0074—remotecgi20 ene 2000
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Media Services 4.0/4.1 - Handshake Sequence Denial of Service
CVE-2000-0211—doswindows18 ene 2000
The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets t
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
A-V Tronics InetServ 3.0 - WebMail GET
CVE-2000-0065—remotewindows17 ene 2000
Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nosque Workshop MsgCore 1.9 - Denial of Service
CVE-2000-0075—doswindows13 ene 2000
Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a den
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Corel Linux OS 1.0 - get_it PATH
CVE-2000-0048—locallinux12 ene 2000
get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp p
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mirabilis ICQ 0.99b 1.1.1.1/3.19 - Remote Buffer Overflow
CVE-2000-0046—remotewindows12 ene 2000
Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PowerScripts PlusMail WebConsole 1.0 - Weak Authentication (1)
CVE-2000-0074—remotecgi11 ene 2000
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat 6.1 / IRIX 6.5.18 - 'lpd' Command Execution
CVE-2000-1221—remoteunix11 ene 2000
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reve
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PowerScripts PlusMail WebConsole 1.0 - Weak Authentication (2)
CVE-2000-0074—remotecgi11 ene 2000
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Qualcomm qpopper 3.0 - 'LIST' Remote Buffer Overflow
CVE-2000-0096—remotelinux10 ene 2000
Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NullSoft Winamp 2.10 - Playlist
CVE-2000-0049—doswindows10 ene 2000
Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4.0/4.0.1/5.0/5.0.1/5.5 - preview Security Zone Settings Lag
CVE-2000-0156—remotewindows07 ene 2000
Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security d
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4.0/4.0.1/5.0/5.0.1/5.5 - preview Security Zone Settings Lag
CVE-2000-0061—remotewindows07 ene 2000
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Phorum 3.0.7 - 'auth.php3' Backdoor Access
CVE-2000-1230—webappsphp06 ene 2000
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with th
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Phorum 3.0.7 - 'admin.php3' Unverified Administrative Password Change
CVE-2000-1228—webappsphp06 ene 2000
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ipswitch IMail 5.0.8/6.0/6.1 - IMonitor 'status.cgi' Denial of Service
CVE-2000-0056—doswindows05 ene 2000
IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Allaire ColdFusion Server 4.0/4.0.1 - 'CFCACHE' Information Disclosure
CVE-2000-0057—remotemultiple04 ene 2000
Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain s
23RIESGO
abrir ↗
← anteriorpágina 617 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.