Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
phpMyNewsletter 0.6.10 - Remote File Inclusion
CVE-2002-1887webappsphp03 out 2002
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - SQL Injection
CVE-2002-0709remotewindows02 out 2002
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to e
23RISCO
abrir
Exploit-DBVexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - File Disclosure
CVE-2002-0708remotewindows02 out 2002
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Midicart PHP - Information Disclosure
CVE-2002-1798webappsphp02 out 2002
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RISCO
abrir
Exploit-DBVexDay Proof
Jetty 3.1.6/3.1.7/4.1 Servlet Engine - Arbitrary Command Execution
CVE-2002-1178webappscgi02 out 2002
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execut
23RISCO
abrir
Exploit-DBVexDay Proof
Py-Membres 3.1 - 'index.php' Unauthorized Access
CVE-2002-1884webappsphp02 out 2002
index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "a
23RISCO
abrir
Exploit-DBVexDay Proof
MySimpleNews 1.0 - PHP Injection
CVE-2002-2319webappsphp02 out 2002
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code an
23RISCO
abrir
Exploit-DBVexDay Proof
Midicart PHP - Arbitrary File Upload
CVE-2002-1798webappsphp02 out 2002
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RISCO
abrir
Exploit-DBVexDay Proof
TightAuction 3.0 - Config.INC Information Disclosure
CVE-2002-1886webappsphp02 out 2002
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote att
23RISCO
abrir
Exploit-DBVexDay Proof
Apache 1.3/2.0.x - Server Side Include Cross-Site Scripting
CVE-2002-0840remotemultiple02 out 2002
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26,
45RISCO
abrir
Exploit-DBVexDay Proof
MySimpleNews 1.0 - Remote Readable Administrator Password
CVE-2002-2143webappsphp02 out 2002
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
phpWebSite 0.8.3 - 'article.php' Cross-Site Scripting
CVE-2002-2178webappsphp02 out 2002
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
Sendmail 8.12.x - SMRSH Double Pipe Access Validation
CVE-2002-1165localunix01 out 2002
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 fro
23RISCO
abrir
Exploit-DBVexDay Proof
Monkey HTTP Server 0.1/0.4/0.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-1852remotemultiple30 set 2002
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir
Exploit-DBVexDay Proof
Rogue 5.3 - Local Buffer Overflow
CVE-2002-1192localbsd30 set 2002
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows
23RISCO
abrir
Exploit-DBVexDay Proof
Sun ONE Starter Kit 2.0 / ASTAware SearchDisc 3.1 - Search Engine Directory Traversal
CVE-2002-1525webappsjava30 set 2002
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to r
23RISCO
abrir
Exploit-DBVexDay Proof
EmuMail 5.0 - Web Root Full Path Disclosure
CVE-2002-1527webappscgi29 set 2002
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed st
23RISCO
abrir
Exploit-DBVexDay Proof
EmuMail 5.0 Email Form - Script Injection
CVE-2002-1526webappscgi29 set 2002
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
SafeTP 1.46 - Passive Mode Internal IP Address Revealing
CVE-2002-1943remotemultiple28 set 2002
SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a
23RISCO
abrir
Exploit-DBVexDay Proof
Jetty 4.1 Servlet Engine - Cross-Site Scripting
CVE-2002-1533webappsjsp28 set 2002
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 2.0.3 - 'calendar.php' Command Execution
CVE-2002-1660webappsphp27 set 2002
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in
28RISCO
abrir
Exploit-DBVexDay Proof
GV 2.x/3.x - '.PDF'/'.PS' File Buffer Overflow (2)
CVE-2002-0838locallinux26 set 2002
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (
23RISCO
abrir
Exploit-DBVexDay Proof
GV 2.x/3.x - '.PDF'/'.PS' File Buffer Overflow (1)
CVE-2002-0838locallinux26 set 2002
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 6.0 - News Message HTML Injection
CVE-2002-1803webappsphp25 set 2002
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir
Exploit-DBVexDay Proof
phpWebSite 0.8.3 - News Message HTML Injection
CVE-2002-2178webappsphp25 set 2002
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
DaCode 1.2 - News Message HTML Injection
CVE-2002-1805webappsphp25 set 2002
Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir
Exploit-DBVexDay Proof
Monkey HTTP Server 0.1.4 - File Disclosure
CVE-2002-2154remotelinux25 set 2002
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (do
23RISCO
abrir
Exploit-DBVexDay Proof
Drupal 4.0 - News Message HTML Injection
CVE-2002-1806webappsphp25 set 2002
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir
Exploit-DBVexDay Proof
ACWeb 1.14/1.8 - Cross-Site Scripting
CVE-2002-2171remotelinux25 set 2002
Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web
23RISCO
abrir
Exploit-DBVexDay Proof
NPDS 4.8 - News Message HTML Injection
CVE-2002-1804webappsphp25 set 2002
Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via
23RISCO
abrir
anteriorpágina 744 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.