Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
ReferênciaVexDay Proof
Portail PHP 1.7 - 'chemin' Remote File Inclusion
CVE-2006-3922webappsphp
PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_colophon' 1.2 - Remote File Inclusion
CVE-2006-3969webappsphp
PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and
23RIESGO
abrir
ReferênciaVexDay Proof
PhpReactor 1.2.7pl1 - 'pathtohomedir' Remote File Inclusion
CVE-2006-3983webappsphp
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
phpAuction 2.1 - 'phpAds_path' Remote File Inclusion
CVE-2006-3984webappsphp
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later vers
23RIESGO
abrir
ReferênciaVexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
CVE-2006-3988webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
k_shoutbox 4.4 - Remote File Inclusion
CVE-2006-3989webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'file_path' Remote File Inclusion
CVE-2006-3991webappsphp
PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
TSEP 0.942 - 'copyright.php' Remote File Inclusion
CVE-2006-3993webappsphp
PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows
23RIESGO
abrir
ReferênciaVexDay Proof
XMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection
CVE-2006-3994webappsphp
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha
23RIESGO
abrir
Referência
CVE-2006-3995
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component User Home Pages 0.5 - Remote File Inclusion
CVE-2006-3995webappsphp
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RIESGO
abrir
ReferênciaVexDay Proof
phpGroupWare 0.9.16.010 - 'GLOBALS[]' Remote Code Execution
CVE-2006-4458webappsphp
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allow
23RIESGO
abrir
Referência
CVE-2009-4562
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
CVE-2006-4489webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
28RIESGO
abrir
ReferênciaVexDay Proof
Pheap CMS 1.1 - 'lpref' Remote File Inclusion
CVE-2006-4531webappsphp
PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Lanifex DMO 2.3b - '_incMgr' Remote File Inclusion
CVE-2006-4604webappsphp
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Be
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4605webappsphp
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4606webappsphp
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
GrapAgenda 0.1 - 'page' Remote File Inclusion
CVE-2006-4610webappsphp
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, a
23RIESGO
abrir
Referência
CVE-2009-4564
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4648webappsphp
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
SL_Site 1.0 - 'spaw_root' Remote File Inclusion
CVE-2006-4656webappsphp
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RIESGO
abrir
ReferênciaVexDay Proof
PhotoKorn Gallery 1.52 - 'dir_path' Remote File Inclusion
CVE-2006-4670webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Fantastic News 2.1.4 - Multiple Remote File Inclusions
CVE-2006-4671webappsphp
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
TIBCO Rendezvous 7.4.11 - Password Extractor
CVE-2006-4676localwindows
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Director < 5.10 - 'Redirect.bat' Directory Traversal
CVE-2006-4681remotewindows
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Vivvo Article Manager 3.2 - 'classified_path' File Inclusion
CVE-2006-4714webappsphp
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RIESGO
abrir
ReferênciaVexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
CVE-2006-4720webappsphp
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
RaidenHTTPD 1.1.49 - 'SoftParserFileXml' Remote Code Execution
CVE-2006-4723remotewindows
PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_global
23RIESGO
abrir
ReferênciaVexDay Proof
Web Server Creator 0.1 - 'l' Remote File Inclusion
CVE-2006-4746webappsphp
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers
23RIESGO
abrir
anteriorpágina 335 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.