Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
PHPartenaire 1.0 - 'dix.php3' Remote File Inclusion
CVE-2006-5032—webappsphp
PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Joomlaboard 1.1.1 - 'sbp' Remote File Inclusion
CVE-2006-5043—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component Security Images 3.0.5 - Remote File Inclusion
CVE-2006-5048—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier f
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263—webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2006-5276—dosmultiple
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
CVE-2006-5296—doswindows
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB lat2cyr Mod 1.0.1 - 'lat2cyr.php' Remote File Inclusion
CVE-2006-5305—webappsphp
PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Open Conference Systems 1.1.4 - 'fullpath' File Inclusion
CVE-2006-5308—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Free Image Hosting 1.0 - 'forgot_pass.php' File Inclusion
CVE-2006-5670—webappsphp
PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
CVE-2006-5627—webappsphp
Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitra
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpDynaSite 3.2.2 - 'racine' Remote File Inclusion
CVE-2006-5760—webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Free File Hosting 1.1 - 'forgot_pass.php' File Inclusion
CVE-2006-5762—webappsphp
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Article System 0.6 - 'volume.php' Remote File Inclusion
CVE-2006-5766—webappsphp
PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
CVE-2006-6038—webappsphp
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
CVE-2006-6250—doswindows
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
CVE-2006-6251—remotewindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RIESGO
abrir ↗
Referência✓ VexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
CVE-2006-6575—webappsphp
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vBlog / C12 0.1 - 'cfgProgDir' Remote File Inclusion
CVE-2006-6586—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6604—webappsphp
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
CVE-2006-6665—localwindows
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6880—webappsphp
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
CVE-2006-6885—doswindows
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890—webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
CVE-2007-0226—webappsphp
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' SSL RSA Private-Key Disclosure
CVE-2007-1376—locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RIESGO
abrir ↗
Referência✓ VexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
CVE-2019-11537—webappsphp
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
CVE-2006-5022—webappsphp
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)
CVE-2023-33584CRITICALwebappsphp
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to
53RIESGO
abrir ↗
Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
CVE-2006-5923—webappsphp
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
CVE-2007-1937—webappsphp
PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
← anteriorpágina 735 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.