Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
Imatix Xitami 2.5 - GSL Template Cross-Site Scripting
CVE-2002-1965remotewindows14 jun 2002
Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to injec
23RISCO
abrir
Exploit-DBVexDay Proof
Ruslan Communications <Body>Builder - Authentication Bypass
CVE-2002-0951webappsjava13 jun 2002
SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--
23RISCO
abrir
Exploit-DBVexDay Proof
Working Resources 1.7.3 BadBlue - Null Byte File Disclosure
CVE-2002-1021remotewindows13 jun 2002
BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a he
23RISCO
abrir
Exploit-DBVexDay Proof
ColdFusion MX - Missing Template Cross-Site Scripting
CVE-2002-1700remotecfm13 jun 2002
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attac
28RISCO
abrir
Exploit-DBVexDay Proof
AnalogX SimpleServer:WWW 1.16 - Web Server Buffer Overflow
CVE-2002-0968remotewindows13 jun 2002
Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash
23RISCO
abrir
Exploit-DBVexDay Proof
Netscape 4.77 - Composer Font Face Field Buffer Overflow
CVE-2002-1766dosmultiple13 jun 2002
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code v
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server 2000 - 'SQLXML' Buffer Overflow (PoC)
CVE-2002-0186doswindows12 jun 2002
Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary
35RISCO
abrir
Exploit-DBVexDay Proof
Macromedia JRun 3/4 JSP Engine - Denial of Service
CVE-2002-0937doswindows12 jun 2002
The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web
23RISCO
abrir
Exploit-DBVexDay Proof
Ayman Akt IRCIT 0.3.1 - Invite Message Remote Buffer Overflow
CVE-2002-1891doslinux12 jun 2002
Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request.
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server 2000 - SQLXML Script Injection
CVE-2002-0187remotewindows12 jun 2002
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute ar
28RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 3/4 - JSP Engine Denial of Service
CVE-2002-0936doslinux12 jun 2002
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the w
28RISCO
abrir
Exploit-DBVexDay Proof
Netscape 4.x/6.x / Mozilla 0.9.x - Malformed Email POP3 Denial of Service
CVE-2002-2338dosmultiple12 jun 2002
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to c
23RISCO
abrir
Exploit-DBVexDay Proof
MakeBook 2.2 - Form Field Input Validation
CVE-2002-0948webappscgi12 jun 2002
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute s
23RISCO
abrir
Exploit-DBVexDay Proof
Richard Gooch SimpleInit 2.0.2 - Open File Descriptor
CVE-2002-0767locallinux12 jun 2002
simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allo
23RISCO
abrir
Exploit-DBVexDay Proof
CGIScript.net csNews 1.0 - Header File Type Restriction Bypass
CVE-2002-0923webappscgi11 jun 2002
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via th
23RISCO
abrir
Exploit-DBVexDay Proof
CGIScript.net csNews 1.0 - Double URL Encoding Unauthorized Administrative Access
CVE-2002-0922webappscgi11 jun 2002
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) defaul
23RISCO
abrir
Exploit-DBVexDay Proof
MyHelpDesk 20020509 - HTML Injection
CVE-2002-0931webappsphp10 jun 2002
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
MyHelpDesk 20020509 - Cross-Site Scripting
CVE-2002-0931webappsphp10 jun 2002
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.5 - Calendar Event Form Script Injection
CVE-2002-0962webappsphp10 jun 2002
Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via
23RISCO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-0962webappsphp10 jun 2002
Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via
23RISCO
abrir
Exploit-DBVexDay Proof
MyHelpDesk 20020509 - SQL Injection
CVE-2002-0932webappsphp10 jun 2002
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
W-Agora 4.1.x - Remote File Inclusion
CVE-2002-1878webappsphp10 jun 2002
PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the i
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris 8 dtspcd - Remote Heap Overflow (Metasploit)
CVE-2001-0803remotesolaris10 jun 2002
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remo
60RISCO
abrir
Exploit-DBVexDay Proof
Seanox DevWex Windows Binary 1.2002.520 - File Disclosure
CVE-2002-0946remotewindows08 jun 2002
Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files vi
23RISCO
abrir
Exploit-DBVexDay Proof
Splatt Forum 3.0 - Image Tag HTML Injection
CVE-2002-0959webappsphp06 jun 2002
Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other user
23RISCO
abrir
Exploit-DBVexDay Proof
Voxel Dot Net CBms 0.x - Multiple Code Injection Vulnerabilities
CVE-2002-0961webappsphp06 jun 2002
Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other
23RISCO
abrir
Exploit-DBVexDay Proof
WebScripts WebBBS 4.x/5.0 - Remote Command Execution
CVE-2002-1993webappscgi06 jun 2002
webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - FTP Web View Cross-Site Scripting
CVE-2002-2062remotewindows06 jun 2002
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with
28RISCO
abrir
Exploit-DBVexDay Proof
Telindus 1100 Series Router - Administration Password Leak
CVE-2002-0949remotehardware05 jun 2002
Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP po
23RISCO
abrir
Exploit-DBVexDay Proof
Slurp 1.10 - SysLog Remote Format String
CVE-2002-0913dosfreebsd04 jun 2002
Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute ar
23RISCO
abrir
anteriorpágina 753 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.