Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISCO
abrir
ReferênciaVexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
CVE-2006-5112remotewindows
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISCO
abrir
ReferênciaVexDay Proof
VideoDB 2.2.1 - 'pdf.php' Remote File Inclusion
CVE-2006-5155webappsphp
PHP remote file inclusion vulnerability in core/pdf.php in VideoDB 2.2.1 and earlier allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Invision Gallery 2.0.7 - 'readfile()' / SQL Injection
CVE-2006-5205webappsphp
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (do
28RISCO
abrir
ReferênciaVexDay Proof
phpMyTeam 2.0 - 'smileys_dir' Remote File Inclusion
CVE-2006-5207webappsphp
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is e
23RISCO
abrir
ReferênciaVexDay Proof
SHTTPD 1.34 - 'POST' Remote Buffer Overflow
CVE-2006-5216remotewindows
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary cod
50RISCO
abrir
ReferênciaVexDay Proof
Freenews 1.1 - 'moteur.php' Remote File Inclusion
CVE-2006-5226webappsphp
PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
OpenDock Easy Gallery 1.4 - 'doc_directory' File Inclusion
CVE-2006-5241webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is en
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component com_registration_detailed 4.1 - Remote File Inclusion
CVE-2006-5254webappsphp
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (
23RISCO
abrir
ReferênciaVexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
CVE-2006-5256webappsphp
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RISCO
abrir
ReferênciaVexDay Proof
PHPMyConferences 8.0.2 - 'menu.inc.php' File Inclusion
CVE-2006-5310webappsphp
PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.
23RISCO
abrir
ReferênciaVexDay Proof
Foafgen 0.3 - 'redir.php' Local Source Disclosure
CVE-2006-5319webappsphp
Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (
23RISCO
abrir
ReferênciaVexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
CVE-2006-5309webappsphp
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RISCO
abrir
ReferênciaVexDay Proof
phpBB SpamOborona Mod 1.0b - Remote File Inclusion
CVE-2006-5385webappsphp
PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows
23RISCO
abrir
ReferênciaVexDay Proof
phpBB PlusXL 2.0_272 - 'constants.php' Remote File Inclusion
CVE-2006-5387webappsphp
PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module
23RISCO
abrir
ReferênciaVexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
CVE-2006-5673webappsphp
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RISCO
abrir
ReferênciaVexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
CVE-2006-5672webappsphp
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
PHP League 0.82 - 'classement.php' SQL Injection
CVE-2006-5676webappsasp
SQL injection vulnerability in consult/classement.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
PHPEasyData Pro 2.2.2 - 'index.php' SQL Injection
CVE-2006-5707webappsphp
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
CVE-2006-5714remotewindows
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RISCO
abrir
ReferênciaVexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
CVE-2006-5715remotewindows
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5725remotewindows
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request
23RISCO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.2.1 - Remote Denial of Service
CVE-2006-5728doswindows
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long
23RISCO
abrir
ReferênciaVexDay Proof
T.G.S. CMS 0.1.7 - 'logout.php' SQL Injection
CVE-2006-5732webappsphp
SQL injection vulnerability in logout.php in T.G.S. CMS 0.1.7 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Friendly 1.0d1 - 'friendly_path' Remote File Inclusion
CVE-2007-2569webappsphp
Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Omni-NFS Server 5.2 - 'nfsd.exe' Remote Stack Overflow (Metasploit)
CVE-2006-5780remotewindows
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RISCO
abrir
ReferênciaVexDay Proof
SAP Web Application Server 6.40 - Arbitrary File Disclosure
CVE-2006-5784remotewindows
Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 a
23RISCO
abrir
ReferênciaVexDay Proof
iPrimal Forums - '/admin/index.php' Change User Password
CVE-2006-5787webappsphp
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwo
23RISCO
abrir
ReferênciaVexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
CVE-2006-5828webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RISCO
abrir
anteriorpágina 168 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.