Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Professional Service Script 1.0 - 'service-list?city' SQL Injection
CVE-2017-17625webappsphp11 dic 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
CVE-2017-17624webappsphp11 dic 2017
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RIESGO
abrir
Exploit-DBVexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
CVE-2017-17623webappsphp11 dic 2017
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
CVE-2017-17622webappsphp11 dic 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
CVE-2017-17621webappsphp11 dic 2017
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RIESGO
abrir
Exploit-DBVexDay Proof
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
CVE-2017-17615webappsphp11 dic 2017
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
CVE-2017-17613webappsphp11 dic 2017
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir
Exploit-DBVexDay Proof
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
CVE-2017-17612webappsphp11 dic 2017
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Advanced Real Estate Script 4.0.7 - SQL Injection
CVE-2017-17603webappsphp11 dic 2017
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir
Exploit-DBVexDay Proof
Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
CVE-2017-17620webappsphp11 dic 2017
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
CVE-2017-17626webappsphp11 dic 2017
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
CVE-2017-17628webappsphp11 dic 2017
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
CVE-2017-17629webappsphp11 dic 2017
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RIESGO
abrir
Exploit-DBVexDay Proof
Advance B2B Script 2.1.3 - 'show_id' / 'pid' SQL Injection
CVE-2017-17602webappsphp09 dic 2017
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection
CVE-2017-17578webappsphp09 dic 2017
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection
CVE-2017-17577webappsphp09 dic 2017
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection
CVE-2017-17576webappsphp09 dic 2017
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection
CVE-2017-17573webappsphp09 dic 2017
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection
CVE-2017-17574webappsphp09 dic 2017
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Foodpanda Clone 1.0 - SQL Injection
CVE-2017-17571webappsphp09 dic 2017
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection
CVE-2017-17600webappsphp09 dic 2017
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection
CVE-2017-17595webappsphp09 dic 2017
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Groupon Clone 1.0 - 'id' SQL Injection
CVE-2017-17575webappsphp09 dic 2017
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection
CVE-2017-17570webappsphp09 dic 2017
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Amazon Clone 1.0 - SQL Injection
CVE-2017-17572webappsphp09 dic 2017
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Freelancer Clone 1.0 - 'profile.php?u' SQL Injection
CVE-2017-17579webappsphp09 dic 2017
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection
CVE-2017-17580webappsphp09 dic 2017
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection
CVE-2017-17588webappsphp09 dic 2017
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Grubhub Clone 1.0 - 'keywords' SQL Injection
CVE-2017-17582webappsphp09 dic 2017
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid' SQL Injection
CVE-2017-17599webappsphp09 dic 2017
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.