Perl Exploits

2,849 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106801 EXPLOITDB perl VERIFIED
EggBlog 4.0 - SQL Injection
by girex
CVE-2008-1639 EXPLOITDB perl VERIFIED
Neat weblog 0.2 - SQL Injection via articleId Parameter
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php.
by Khashayar Fereidani
CVE-2008-1712 EXPLOITDB perl VERIFIED
mxBB 2.0.0 beta - Remote Code Execution via mx_root_path Parameter
PHP remote file inclusion vulnerability in includes/functions_weblog.php in mxBB mx_blogs 2.0.0 beta allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.
by bd0rk
CVE-2008-1715 EXPLOITDB perl VERIFIED
AuraCMS < 2.2.1 - SQL Injection via Country Parameter
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.
by NTOS-Team
CVE-2008-1607 EXPLOITDB perl VERIFIED
Serbay Arslanhan Bomba Haber 2.0 - SQL Injection
SQL injection vulnerability in haberoku.php in Serbay Arslanhan Bomba Haber 2.0 allows remote attackers to execute arbitrary SQL commands via the haber parameter.
by cOndemned
CVE-2008-1558 EXPLOITDB perl VERIFIED
MPlayer - Remote Code Execution via Large streamid SDP Parameter
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.
by Guido Landi
CVE-2008-1539 EXPLOITDB perl VERIFIED
PHP-Nuke Platinum 7.6.b.5 - SQL Injection
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums module.
by Inphex
CVE-2008-1680 EXPLOITDB perl VERIFIED
PHP-Nuke Platinum 7.6.b.5 - Info Disclosure
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.
by Inphex
EIP-2026-116355 EXPLOITDB perl VERIFIED
Surgemail 3.8 - IMAP LSUB Command Remote Stack Buffer Overflow
by Leon Juranic
CVE-2008-1509 EXPLOITDB perl VERIFIED
xlportal < 2.2.4 - SQL Injection via Query Parameter
SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the query parameter.
by cOndemned
CVE-2008-1478 EXPLOITDB perl VERIFIED
Home FTP Server 1.4.5.89 - Denial of Service via Passive Mode Connection Handling
Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode connection, then closing the original FTP connection. NOTE: some of these details are obtained from third party information.
by 0in
CVE-2008-1276 EXPLOITDB perl VERIFIED
MailEnable Professional/Enterprise <3.13 - Authenticated RCE via IMAP Commands
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execute arbitrary code via long arguments to the (1) FETCH, (2) EXAMINE, and (3) UNSUBSCRIBE commands.
by haluznik
CVE-2008-1398 EXPLOITDB perl VERIFIED
AuraCMS 2.0-2.2.1 - SQL Injection via X-Forwarded-For Header
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.
by NTOS-Team
CVE-2008-1117 EXPLOITDB perl VERIFIED
Timbuktu Pro 8.6.5 - Path Traversal and Arbitrary File Write via Notes Feature
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot slash) sequences. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4220.
by titon
CVE-2008-1219 EXPLOITDB perl VERIFIED
Kutub-i Sitte <1.1 - SQL Injection
SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the kid parameter in a hadisgoster action to modules.php.
by r080cy90r
CVE-2008-1121 EXPLOITDB perl VERIFIED
eazyportal < 1.0 - SQL Injection via session_vars Cookie
SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the session_vars cookie.
by Iron
CVE-2008-5582 EXPLOITDB perl VERIFIED
Nukedit 4.9.x - SQL Injection via Email Parameter
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.
by r3dm0v3
CVE-2008-1038 EXPLOITDB perl VERIFIED
DBHcms - Remote Code Execution via extmanager_install Parameter
PHP remote file inclusion vulnerability in mod/mod.extmanager.php in DBHcms 1.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the extmanager_install parameter.
by Iron
CVE-2008-0830 EXPLOITDB perl VERIFIED
iPhoto 4.0.3 - Denial of Service via Malformed DPAP URI
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.
by David Wharton
CVE-2008-0835 EXPLOITDB perl VERIFIED
Simple CMS <= 1.0.3 - SQL Injection via Area Parameter
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the area parameter.
by JosS
CVE-2008-1176 EXPLOITDB perl VERIFIED
Affiliate Market 0.1 BETA - Cross-Site Scripting via sideblock4 Parameter
Cross-site scripting (XSS) vulnerability in function/sideblock.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to inject arbitrary web script or HTML via the sideblock4 parameter.
by Khashayar Fereidani
CVE-2007-6478 EXPLOITDB perl VERIFIED
Rosoft Media Player <4.1.8 - Buffer Overflow
Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a .M3U file. NOTE: some of these details are obtained from third party information.
by securfrog
CVE-2008-0802 EXPLOITDB perl VERIFIED
MediaSlide (com_mediaslide) 0.5 - SQL Injection via albumnum Parameter
SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action.
by Inphex
CVE-2008-1177 EXPLOITDB perl VERIFIED
Affiliate Market 0.1 BETA - SQL Injection
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execute arbitrary SQL commands via the id parameter.
by Khashayar Fereidani
EIP-2026-113135 EXPLOITDB perl VERIFIED
vKios 2.0.0 - 'cat' SQL Injection
by NTOS-Team