Perl Exploits
2,854 exploits tracked across all sources.
Ryneezy phoSheezy 0.2 - Code Injection
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information.
by Osirys
Ryneezy phoSheezy 0.2 - Info Disclosure
Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password.
by Osirys
Ryneezy phoSheezy 0.2 - Code Injection
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Osirys
dBpowerAMP Audio Player 2 - '.pls' Local Buffer Overflow (PoC)
by Stack
Microsoft HTML Help Workshop <4.74 - Buffer Overflow
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.
by SkD
Simple Machines Forum (SMF) 1.0.13/1.1.5 - 'Destroyer 0.1' Password Reset Security Bypass
by Xianur0
VUPlayer 2.49 - Buffer Overflow
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.
by sCORPINo
Microsoft Windows XP SP3 - Buffer Overflow
Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.
by securfrog
Browse3D 3.5 - '.sfs' Local Buffer Overflow (PoC)
by Houssamix
Joomla! Component com_jashowcase - 'catid' SQL Injection
by EcHoLL
VUPlayer 2.49 - Buffer Overflow
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.
by Houssamix
VUPlayer 2.49 - Buffer Overflow
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.
by aBo MoHaMeD
Heathco Software MP3 TrackMaker <1.5 - Buffer Overflow
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.
by Houssamix
VUPlayer <2.49 - RCE
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.
by SkD
CVSS 8.8
CoolPlayer 2.19 - 'PlaylistSkin' Local Buffer Overflow
by Jeremy Brown
Cain & Abel 4.9.25 - 'Cisco IOS-MD5' Local Buffer Overflow
by send9
Winamp 5.541 - gen_msn.dll Buffer Overflow
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field. NOTE: some of these details are obtained from third party information.
by SkD
Perception LiteServe 2.0.1 - 'user' Remote Buffer Overflow (PoC)
by Houssamix
Goople CMS <1.8.2 - SQL Injection
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
by darkjoker
Rosoft Media Player 4.2.1 - Local Buffer Overflow
by Encrypt3d.M!nd
Goople CMS 1.8.2 - SQL Injection
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by darkjoker
By Source