Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
OmniHTTPd 1.1/2.0.x/2.4 - 'test.php' Sample Application Cross-Site Scripting
CVE-2002-1455remotewindows26 ago 2002
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into we
23RISCO
abrir
Exploit-DBVexDay Proof
OmniHTTPd 1.1/2.0.x/2.4 - test.shtml Sample Application Cross-Site Scripting
CVE-2002-1455remotewindows26 ago 2002
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into we
23RISCO
abrir
Exploit-DBVexDay Proof
Belkin F5D6130 Wireless Network Access Point - SNMP Request Denial of Service
CVE-2002-1811doshardware26 ago 2002
Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of servic
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Word 95/97/98/2000/2002 / Excel 2002 - INCLUDETEXT Document Sharing File Disclosure
CVE-2002-1143remotewindows26 ago 2002
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the i
35RISCO
abrir
Exploit-DBVexDay Proof
Blazix 1.2 - Password Protected Directory Information Disclosure
CVE-2002-1451remotemultiple25 ago 2002
Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an
23RISCO
abrir
Exploit-DBVexDay Proof
PHPReactor 1.2.7 - Style Attribute HTML Injection
CVE-2002-2424webappsphp24 ago 2002
Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
Blazix 1.2 - Special Character Handling Server Side Script Information Disclosure
CVE-2002-1451remotemultiple24 ago 2002
Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an
23RISCO
abrir
Exploit-DBVexDay Proof
GDAM123 0.933/0.942 - Filename Buffer Overflow
CVE-2002-1812localunix24 ago 2002
Buffer overflow in gdam123 0.933 and 0.942 allows local users to execute arbitrary code via a long filename parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - XML Redirect File Disclosure
CVE-2002-0648remotewindows23 ago 2002
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attac
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Network Share Provider SMB Request Buffer Overflow (2)
CVE-2002-0724doswindows22 ago 2002
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows atta
28RISCO
abrir
Exploit-DBVexDay Proof
Abyss Web Server 1.0 - Encoded Backslash Directory Traversal
CVE-2002-1079remotewindows22 ago 2002
Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Network Share Provider SMB Request Buffer Overflow (1)
CVE-2002-0724doswindows22 ago 2002
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows atta
28RISCO
abrir
Exploit-DBVexDay Proof
Achievo 0.7/0.8/0.9 - Remote File Inclusion / Command Execution
CVE-2002-1435webappsphp22 ago 2002
class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 Legacy Text Formatting - ActiveX Component Buffer Overflow
CVE-2002-0647remotewindows22 ago 2002
Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01
28RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 4.1 - JSP Request Cross-Site Scripting
CVE-2002-1567remoteunix21 ago 2002
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script an
28RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Bonsai - Multiple Cross-Site Scripting Vulnerabilities
CVE-2003-0154webappscgi20 ago 2002
Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Bonsai 1.3 - Full Path Disclosure
CVE-2003-0153webappscgi20 ago 2002
bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.
23RISCO
abrir
Exploit-DBVexDay Proof
Novell NetWare 5.1/6.0 - POST Arbitrary Perl Code Execution
CVE-2002-1436remotenovell20 ago 2002
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl cod
23RISCO
abrir
Exploit-DBVexDay Proof
SCPOnly 2.3/2.4 - SSH Environment Shell Escaping
CVE-2002-1469locallinux20 ago 2002
scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote
23RISCO
abrir
Exploit-DBVexDay Proof
Kerio MailServer 5.0/5.1 Web Mail - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-1434webappscgi19 ago 2002
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
MySQL 3.20.32/3.22.x/3.23.x - Null Root Password Weak Default Configuration (1)
CVE-2002-1809remotelinux19 ago 2002
The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which
28RISCO
abrir
Exploit-DBVexDay Proof
Lynx 2.8.x - Command Line URL CRLF Injection
CVE-2002-1405remotelinux19 ago 2002
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP
23RISCO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 0.15.x/0.16/0.17.x - JPGraph Remote File Inclusion Command Execution
CVE-2002-1113webappsphp19 ago 2002
summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modify
23RISCO
abrir
Exploit-DBVexDay Proof
Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Modification
CVE-2002-1422webappsphp19 ago 2002
admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in th
23RISCO
abrir
Exploit-DBVexDay Proof
Ilia Alshanetsky FUDForum 1.2.8/1.9.8/2.0.2 - File Disclosure
CVE-2002-1423webappsphp19 ago 2002
tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the fi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 4/5/6 - XML Datasource Applet File Disclosure
CVE-2002-0976localwindows17 ago 2002
Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XM
28RISCO
abrir
Exploit-DBVexDay Proof
Apache 2.0 - Full Path Disclosure
CVE-2002-0654remotewindows16 ago 2002
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the ser
35RISCO
abrir
Exploit-DBVexDay Proof
SGI IRIX 6.5.x - FAM Arbitrary Root Owned Directory File Listing
CVE-2002-0875localirix16 ago 2002
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose acces
23RISCO
abrir
Exploit-DBVexDay Proof
Google Toolbar 1.1.60 - Search Function Denial of Service
CVE-2002-1444doswindows15 ago 2002
The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of s
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft SQL 2000/7.0 - Agent Jobs Privilege Escalation
CVE-2002-0721remotewindows15 ago 2002
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with
35RISCO
abrir
anteriorpágina 747 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.