Perl Exploits
2,849 exploits tracked across all sources.
YABB SE 0.8/1.4/1.5 - 'Packages.php' Remote File Inclusion
by spabam
Apache Web Server 2.0.x - MS-DOS Device Name Denial of Service
by Matthew Murphy
phpBB <= 2.0.3 - SQL Injection via privmsg.php mark[] Parameter
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.
by Ulf Harnhammar
CSO Lanifex Outreach Project Tool 0.946b - Request Origin Spoofing
by Martin Eiszner
Psunami Bulletin Board 0.x - 'Psunami.cgi' Remote Command Execution (2)
by spabam
Psunami Bulletin Board 0.x - 'Psunami.cgi' Remote Command Execution (1)
by dodo
SGI IRIX - Buffer Overflow in Login via Telnet/Rlogin Arguments
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
by snooq
etype eserv 2.92-2.98 - Denial of Service via Large Data Input
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
by D4rkGr3y
etype eserv 2.92-2.98 - Denial of Service via Large Data Input
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
by D4rkGr3y
etype eserv 2.92-2.98 - Denial of Service via Large Data Input
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
by D4rkGr3y
etype eserv 2.92-2.98 - Denial of Service via Large Data Input
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
by D4rkGr3y
chetcpasswd < 2.1 - Unauthenticated Shadow File Information Disclosure via Long User Field
chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field.
by Victor Pereira
PC-cillin <2003 - RCE
Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).
by Joel Soderberg
Enceladus Server Suite 3.9 - Remote Code Execution via Long CD Command
Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.
by Tamer Sahin
Apache Tomcat 4.0-4.1.12 with mod_jk 1.2.1 - Denial of Service via Invalid Chunked Transfer-Encoding
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
by Sapient2003
Pserv 2.0 - User-Agent HTTP Header Buffer Overflow (1)
by Sapient2003
XFS font server <9 - Buffer Overflow
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
by TESO Security
WSMP3 0.0.1/0.0.2 - Remote Heap Corruption (1)
by Damian Myerscough
Zeroo http_server 1.5 - Path Traversal via URL GET Request
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.
by mattmurphy
tftpd32 < 2.21 - Remote Code Execution via Long Filename
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.
by Aviram Jenik
IISPop 1.161 and 1.181 - Denial of Service via Long POP3 Request
Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110).
by securma massine
Perception LiteServe <2.0.1 - Info Disclosure
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").
by mattmurphy
KeyFocus kf_web_server 1.0.8 - Path Traversal via Multiple Dot Sequences
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
by mattmurphy
Pserv 2.0 - HTTP Request Parsing Buffer Overflow
by Matthew Murphy
By Source