Perl Exploits

2,854 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-118083 EXPLOITDB perl VERIFIED
VUPlayer 2.49 - '.wax' Local Buffer Overflow
by Houssamix
CVE-2009-0702 EXPLOITDB perl VERIFIED
Joomla! - SQL Injection
SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.
by EcHoLL
EIP-2026-108452 EXPLOITDB perl VERIFIED
Joomla! Component com_na_newsdescription - 'newsid' SQL Injection
by EcHoLL
CVE-2009-0701 EXPLOITDB perl VERIFIED
Cybershade CMS 0.2b - RCE
Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) THEME_header and (2) THEME_footer parameters.
by JosS
EIP-2026-117032 EXPLOITDB perl VERIFIED
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (4)
by Stack
EIP-2026-117031 EXPLOITDB perl VERIFIED
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (3)
by Houssamix
EIP-2026-117030 EXPLOITDB perl VERIFIED
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (2)
by sCORPINo
CVE-2009-3429 EXPLOITDB perl VERIFIED
Pirateradio Destiny Media Player - Memory Corruption
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.
by Encrypt3d.M!nd
EIP-2026-112639 EXPLOITDB perl VERIFIED
The Rat CMS Alpha 2 - Blind SQL Injection
by darkjoker
CVE-2009-0592 EXPLOITDB perl VERIFIED
PNphpBB2 <1.2i - Path Traversal
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ModName parameter to (1) admin_words.php, (2) admin_groups_reapir.php, (3) admin_smilies.php, (4) admin_ranks.php, (5) admin_styles.php, and (6) admin_users.php in admin/.
by StAkeR
CVE-2009-3429 EXPLOITDB perl VERIFIED
Pirateradio Destiny Media Player - Memory Corruption
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.
by Encrypt3d.M!nd
EIP-2026-102552 EXPLOITDB perl VERIFIED
aMSN - '.ctt' Remote Denial of Service
by Hakxer
CVE-2009-3429 EXPLOITDB perl VERIFIED
Pirateradio Destiny Media Player - Memory Corruption
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.
by aBo MoHaMeD
CVE-2009-0491 EXPLOITDB perl VERIFIED
Elecard MPEG Player <5.5 - Buffer Overflow
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL.
by aBo MoHaMeD
CVE-2009-0490 EXPLOITDB perl VERIFIED
Audacity <1.3.6 - Buffer Overflow
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.
by Houssamix
CVE-2009-0711 EXPLOITDB perl VERIFIED
PHPFootball <1.6 - Info Disclosure
filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.
by KinG-LioN
CVE-2008-5821 EXPLOITDB perl VERIFIED
WebKit <3.2 - DoS
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.
by Jeremy Brown
CVE-2008-6727 EXPLOITDB perl VERIFIED
Upb - XSS
Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
by StAkeR
CVE-2008-4844 EXPLOITDB perl VERIFIED
Microsoft Internet Explorer - Resource Management Error
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
by Jeremy Brown
EIP-2026-118254 EXPLOITDB perl VERIFIED
Amaya Web Browser 11.0.1 (Windows Vista) - Remote Buffer Overflow
by SkD
CVE-2008-5756 EXPLOITDB perl VERIFIED
Hex Workshop 5.1.4 - Buffer Overflow
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service and possibly execute arbitrary code via a long mapping reference in a Color Mapping (.cmap) file.
by Encrypt3d.M!nd
CVE-2008-5754 EXPLOITDB perl VERIFIED
BulletProof FTP Client - Buffer Overflow
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to CVE-2008-5753.
by Stack
CVE-2008-6731 EXPLOITDB perl VERIFIED
China-on-site Flexphplink - Improper Input Validation
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the renamed file in linkphoto/.
by Osirys
CVE-2008-6146 EXPLOITDB perl VERIFIED
Deluxebb < 1.2 - SQL Injection
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989.
by StAkeR
CVE-2008-5874 EXPLOITDB perl VERIFIED
Hotel Booking Reservation System - Joomla! SQL Injection
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained from third party information.
by EcHoLL