Perl Exploits

2,849 exploits tracked across all sources.

Sort: Activity Stars
CVE-2009-1667 EXPLOITDB perl VERIFIED
Mini-stream CastRipper 2.50.70 - Stack-based Buffer Overflow via Long Entry in .m3u File
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long entry in a .m3u file, a different vector than CVE-2009-5137.
by Stack
CVE-2009-1667 EXPLOITDB perl VERIFIED
Mini-stream CastRipper 2.50.70 - Stack-based Buffer Overflow via Long Entry in .m3u File
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long entry in a .m3u file, a different vector than CVE-2009-5137.
by [0]x80->[H]4x²0r
CVE-2009-1778 EXPLOITDB perl VERIFIED
BigACE CMS 2.5 - SQL Injection via Username Parameter
SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
by YEnH4ckEr
EIP-2026-118773 EXPLOITDB perl VERIFIED
Mereo 1.8.0 - Arbitrary File Disclosure
by Cyber-Zone
CVE-2009-1661 EXPLOITDB perl VERIFIED
uTopic 1.0 - SQL Injection via Rating Parameter
SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.
by YEnH4ckEr
EIP-2026-106802 EXPLOITDB perl VERIFIED
EggBlog 4.1.1 - Local Directory Traversal
by StAkeR
CVE-2009-1660 EXPLOITDB perl VERIFIED
ViPlay3 3.0 and earlier - Stack-based Buffer Overflow via Long File Entry in .vpl File
Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file entry in a .vpl file.
by LiquidWorm
CVE-2009-1910 EXPLOITDB perl VERIFIED
RTWebalbum 1.0.462 - SQL Injection via AlbumId Parameter
SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands via the AlbumId parameter.
by YEnH4ckEr
CVE-2009-1643 EXPLOITDB perl VERIFIED
Soritong MP3 Player 1.0 - Stack-Based Buffer Overflow via Crafted .m3u File
Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file.
by Stack
CVE-2009-1644 EXPLOITDB perl VERIFIED
Sorinara Streaming Audio Player 0.9 - Stack-based Buffer Overflow via Crafted PLA File
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.
by Hakxer
CVE-2009-1646 EXPLOITDB perl VERIFIED
Mini-stream RM Downloader 3.0.0.9 - Stack-based Buffer Overflow via Long RTSP URL
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.
by G4N0K
CVE-2009-1645 EXPLOITDB perl VERIFIED
Mini-stream Easy RM-MP3 Converter 3.0.0.7 - Remote Code Execution via Long RTSP URL or HREF Attribute
Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.
by G4N0K
CVE-2009-1645 EXPLOITDB perl VERIFIED
Mini-stream Easy RM-MP3 Converter 3.0.0.7 - Remote Code Execution via Long RTSP URL or HREF Attribute
Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.
by G4N0K
CVE-2009-1641 EXPLOITDB perl VERIFIED
Mini-stream Ripper 3.0.1.1 - Remote Code Execution via Long RTSP URL or HREF Attribute
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.
by G4N0K
CVE-2009-1641 EXPLOITDB perl VERIFIED
Mini-stream Ripper 3.0.1.1 - Remote Code Execution via Long RTSP URL or HREF Attribute
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.
by G4N0K
CVE-2009-1642 EXPLOITDB perl VERIFIED
Mini-stream ASX to MP3 Converter 3.0.0.7 - Stack-based Buffer Overflow via Long rtsp URL or HREF Attribute
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. NOTE: the latter was also subsequently reported in "prior to 3.1.3.7."
by G4N0K
CVE-2009-1642 EXPLOITDB perl VERIFIED
Mini-stream ASX to MP3 Converter 3.0.0.7 - Stack-based Buffer Overflow via Long rtsp URL or HREF Attribute
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. NOTE: the latter was also subsequently reported in "prior to 3.1.3.7."
by G4N0K
CVE-2009-1586 EXPLOITDB perl VERIFIED
GrabIt < 1.7.2 Beta 3 - Stack-Based Buffer Overflow via NZB File DTD Reference
Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.
by Jeremy Brown
CVE-2009-1644 EXPLOITDB perl VERIFIED
Sorinara Streaming Audio Player 0.9 - Stack-based Buffer Overflow via Crafted PLA File
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.
by GoLd_M
CVE-2009-1912 EXPLOITDB perl VERIFIED
webSPELL < 4.2.0e - Path Traversal via Language Cookie
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.
by DNX
CVE-2009-1592 EXPLOITDB perl VERIFIED
ElectraSoft 32bit FTP 09.04.24 - Stack-based Buffer Overflow via Long FTP Banner
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. NOTE: this might overlap CVE-2003-1368.
by Load 99%
CVE-2009-2568 EXPLOITDB perl VERIFIED
Sorinara Streaming Audio Player 0.9 - Remote Code Execution via Long String in Playlist File
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.
by Stack
CVE-2009-1586 EXPLOITDB perl VERIFIED
GrabIt < 1.7.2 Beta 3 - Stack-Based Buffer Overflow via NZB File DTD Reference
Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.
by Gaurav Baruah
CVE-2009-2568 EXPLOITDB perl VERIFIED
Sorinara Streaming Audio Player 0.9 - Remote Code Execution via Long String in Playlist File
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.
by Cyber-Zone
CVE-2009-1584 EXPLOITDB perl VERIFIED
TemaTres 1.0.3 and 1.031 - SQL Injection via Multiple Parameters
Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) mail, (2) password, and (3) letra parameters to index.php; (4) y and (5) m parameters to sobre.php; and the (6) dcTema, (7) madsTema, (8) zthesTema, (9) skosTema, and (10) xtmTema parameters to xml.php.
by YEnH4ckEr