Perl Exploits

2,849 exploits tracked across all sources.

Sort: Activity Stars
CVE-2008-6617 EXPLOITDB perl VERIFIED
SiteXS CMS 0.1.1 - Unauthenticated Arbitrary File Upload via adm/visual/upload.php
Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.
by Hadi Kiamarsi
EIP-2026-109029 EXPLOITDB perl VERIFIED
KnowledgeQuest 2.6 - Administration Multiple Authentication Bypass Vulnerabilities
by Cod3rZ
CVE-2008-6653 EXPLOITDB perl VERIFIED
com_webhosting < 1.1 - SQL Injection via catid Parameter
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
by cO2
EIP-2026-110020 EXPLOITDB perl VERIFIED
ODFaq 2.1.0 - Blind SQL Injection
by cO2
EIP-2026-108823 EXPLOITDB perl VERIFIED
Joomla! Component paxxgallery 0.2 - 'gid' Blind SQL Injection
by ZAMUT
CVE-2008-1559 EXPLOITDB perl VERIFIED
Joomla! com_alphacontent 2.5.8 - SQL Injection
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
by cO2
CVE-2008-1608 EXPLOITDB perl VERIFIED
Clever Copy 3.0 - SQL Injection via ID Parameter
SQL injection vulnerability in postview.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter, a different vector than CVE-2008-0363 and CVE-2006-0583.
by U238
EIP-2026-114552 EXPLOITDB perl VERIFIED
YouTube Clone Script - 'spages.php' Remote Code Execution
by Inphex
CVE-2008-1954 EXPLOITDB perl VERIFIED
Web Calendar Pro <4.1 - SQL Injection
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
by t0pP8uZz
EIP-2026-114475 EXPLOITDB perl VERIFIED
XOOPS Module Recipe 2.2 - 'detail.php' SQL Injection
by S@BUN
CVE-2008-6523 EXPLOITDB perl VERIFIED
openInvoice 0.90 beta and earlier - Unauthenticated Authentication Bypass via oiauth Cookie
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users.
by t0pP8uZz
CVE-2008-6524 EXPLOITDB perl VERIFIED
openInvoice < 0.90 - Authenticated Arbitrary Password Reset via UID Parameter
resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.
by t0pP8uZz
CVE-2008-1912 EXPLOITDB perl VERIFIED
DivX Player <6.7.0.22 - Buffer Overflow
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.
by securfrog
CVE-2007-6584 EXPLOITDB perl VERIFIED
1024 CMS 1.3.1 - Path Traversal via Lang or Theme Parameters
Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang parameter to pages/print/default/ops/news.php or (2) the theme_dir parameter to pages/download/default/ops/search.php; or the admin_theme_dir parameter to (3) download.php, (4) forum.php, or (5) news.php in admin/ops/reports/ops/. NOTE: it was later reported that 1.4.2 beta and earlier are also affected for vector 1.
by girex
CVE-2008-1911 EXPLOITDB perl VERIFIED
1024 CMS 1.4.2 beta and earlier - SQL Injection via cookpass Cookie
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a cookpass cookie.
by girex
CVE-2008-1910 EXPLOITDB perl VERIFIED
Borland InterBase 2007 SP2 - Buffer Overflow
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers to execute arbitrary code via a malformed opcode 0x52 request to TCP port 3050. NOTE: this might overlap CVE-2007-5243 or CVE-2007-5244.
by Liu Zhen Hua
CVE-2008-1750 EXPLOITDB perl VERIFIED
Integry Systems LiveCart <1.1.1 - SQL Injection
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI.
by irvian
CVE-2008-6537 EXPLOITDB perl VERIFIED
LightNEasy 1.2 - Unauthenticated Administrator Password Hash Exposure via Setup Action
LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared from $_GET but later accessed using $_REQUEST.
by girex
CVE-2008-1727 EXPLOITDB perl VERIFIED
KnowledgeQuest 2.5 and 2.6 - Unauthenticated Arbitrary Admin Account Creation via admincheck.php
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.
by t0pP8uZz
CVE-2008-1860 EXPLOITDB perl VERIFIED
LokiCMS < 0.3.3 - Remote Code Execution via Default Parameter
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.
by girex
EIP-2026-111270 EXPLOITDB perl VERIFIED
Picture Rating 1.0 - Blind SQL Injection
by t0pP8uZz
CVE-2008-1874 EXPLOITDB perl VERIFIED
xpoze_pro < 3.05 - Authenticated SQL Injection via reed Parameter
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to execute arbitrary SQL commands via the reed parameter.
by t0pP8uZz
CVE-2008-1870 EXPLOITDB perl VERIFIED
PIGMy-SQL <= 1.4.1 - SQL Injection via getdata.php id Parameter
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by t0pP8uZz
CVE-2008-0069 EXPLOITDB perl VERIFIED
XnView < 1.92 - Stack-based Buffer Overflow via Long FontName Parameter in Slideshow File
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461.
by haluznik
CVE-2008-1713 EXPLOITDB perl VERIFIED
NoticeWare Email Server <4.6.1.0 - DoS
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP port (143/tcp).
by Ray