Perl Exploits

2,854 exploits tracked across all sources.

Sort: Activity Stars
CVE-2003-0325 EXPLOITDB perl VERIFIED
Maelstrom <3.0.6-3.0.5 - RCE
Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.
by Luca Ercoli
CVE-2003-0289 EXPLOITDB perl VERIFIED
cdrecord <2.0 - Privilege Escalation
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.
by anonymous
CVE-2004-2720 EXPLOITDB perl VERIFIED
Snitz Communications Snitz Forums 2000 < 3.4.04 - XSS
Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.
by anonymous
CVE-2003-0290 EXPLOITDB perl VERIFIED
eServ <2.9x - DoS
Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.
by Matthew Murphy
CVE-2003-0280 EXPLOITDB perl VERIFIED
CMailServer 4.0.2003.03 - Buffer Overflow
Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.
by Dennis Rand
CVE-2003-0280 EXPLOITDB perl VERIFIED
CMailServer 4.0.2003.03 - Buffer Overflow
Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.
by Dennis Rand
EIP-2026-100564 EXPLOITDB perl VERIFIED
Snitz Forums 2000 - 'register.asp' SQL Injection
by sharpiemarker
CVE-2003-1473 EXPLOITDB perl VERIFIED
Lgames Ltris - Memory Corruption
Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.
by Knud Erik Hojgaard
CVE-2003-0274 EXPLOITDB perl VERIFIED
catmail <8.2.09 - RCE
Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.
by kf
CVE-2003-0243 EXPLOITDB perl VERIFIED
Happycgi.com Happymall <4.4 - RCE
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.
by Revin Aldi
CVE-2003-0243 EXPLOITDB perl VERIFIED
Happycgi.com Happymall <4.4 - RCE
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.
by Revin Aldi
CVE-2003-0263 EXPLOITDB perl VERIFIED
Floosietek FTGate Pro Mail Server <1.22 - RCE
Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.
by Dennis Rand
CVE-2003-0263 EXPLOITDB perl VERIFIED
Floosietek FTGate Pro Mail Server <1.22 - RCE
Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.
by Dennis Rand
CVE-2003-0269 EXPLOITDB perl VERIFIED
youbin - Buffer Overflow
Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.
by Knud Erik Hojgaard
CVE-2003-1481 EXPLOITDB perl VERIFIED
Stalker Communigate Pro - Information Disclosure
CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.
by Yaroslav Polyakov
CVE-2003-0770 EXPLOITDB perl VERIFIED
IkonBoard <3.1.2a - RCE
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.
by snooq
EIP-2026-100902 EXPLOITDB perl VERIFIED
Stockman Shopping Cart 7.8 - Arbitrary Command Execution
by Aleksey Sintsov
CVE-2003-1396 EXPLOITDB perl VERIFIED
Opera Browser < 7.10 - Out-of-Bounds Write
Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.
by imagine & nesumin
CVE-2003-1472 EXPLOITDB perl VERIFIED
3d-ftp - Memory Corruption
Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.
by Over_G
CVE-2003-1456 EXPLOITDB perl VERIFIED
Mike Bobbitt Album.pl < 6.1 - Improper Input Validation
Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.
CVE-2003-0390 EXPLOITDB perl VERIFIED
Options Parsing Tool <3.18 - Buffer Overflow
Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.
by jlanthea
CVE-2003-0113 EXPLOITDB perl VERIFIED
Microsoft IE - Buffer Overflow
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.
by Jouko Pynnonen
CVE-2003-0265 EXPLOITDB perl VERIFIED
SAP Database 7.3.0.29 - Privilege Escalation
Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.
by Larry W. Cashdollar
EIP-2026-116589 EXPLOITDB perl VERIFIED
Xeneo Web Server 2.2.9.0 - Denial of Service
by Tom Ferris
EIP-2026-104125 EXPLOITDB perl VERIFIED
Web Protector 2.0 - Trivial Encryption
by rjfix