Perl Exploits

2,849 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-115175 EXPLOITDB perl VERIFIED
DzSoft PHP Editor 3.1.2.8 - Denial of Service
by basher13
EIP-2026-118302 EXPLOITDB perl VERIFIED
Baby Web Server 2.6.2 - Command Validation
by basher13
EIP-2026-116177 EXPLOITDB perl VERIFIED
Remote File Explorer 1.0 - Denial of Service
by basher13
EIP-2026-114898 EXPLOITDB perl VERIFIED
AnalogX SimpleServer:WWW 1.05 - Denial of Service
by Qnix
EIP-2026-101205 EXPLOITDB perl VERIFIED
Cisco VoIP Phone CP-7940 3.x - Spoofed SIP Status Message Handling
by DrFrancky
EIP-2026-100794 EXPLOITDB perl VERIFIED
eRoom 6.0 PlugIn - Insecure File Download Handling
by c0ntex
CVE-2005-2106 EXPLOITDB perl VERIFIED
Drupal 4.5.0-4.5.3, 4.6.0-4.6.1 - Remote Code Execution via Public Comment or Posting
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.
by dab
CVE-2005-2113 EXPLOITDB perl VERIFIED
XOOPS <= 2.0.11 - SQL Injection via XMLRPC LoginUser Function
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.
by RusH
CVE-2005-1921 EXPLOITDB perl VERIFIED
PEAR XML_RPC < 1.3.0 and PHPXMLRPC < 1.1 - Remote Code Execution via Unsanitized XML Input
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
by Mike Rifone
CVE-2005-1921 EXPLOITDB perl VERIFIED
PEAR XML_RPC < 1.3.0 and PHPXMLRPC < 1.1 - Remote Code Execution via Unsanitized XML Input
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.
by dukenn
EIP-2026-110948 EXPLOITDB perl VERIFIED
phpBB 2.0.15 - 'highlight' Database Authentication Details
by SecureD
CVE-2005-1524 EXPLOITDB perl VERIFIED
Cacti < 0.8.6d - Remote Code Execution via top_graph_header.php config[library_path] Parameter
PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_path] parameter.
by Alberto Trivero
CVE-2005-2108 EXPLOITDB perl VERIFIED
WordPress <= 1.5.1.2 - SQL Injection via HTTP_RAW_POST_DATA
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.
by GulfTech Security
EIP-2026-100779 EXPLOITDB perl VERIFIED
Community Link Pro - 'login.cgi?File' Remote Command Execution
by spher3
EIP-2026-116071 EXPLOITDB perl VERIFIED
PlanetDNS PlanetFileServer - Remote Buffer Overflow (PoC)
by fRoGGz
CVE-2005-2085 EXPLOITDB perl VERIFIED
Inframail Advantage Server Edition 6.0-6.7 - Denial of Service via Long SMTP FROM Field or FTP NLST Command
Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.
by Reed Arvin
CVE-2005-2085 EXPLOITDB perl VERIFIED
Inframail Advantage Server Edition 6.0-6.7 - Denial of Service via Long SMTP FROM Field or FTP NLST Command
Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.
by Reed Arvin
CVE-2005-2066 EXPLOITDB perl VERIFIED
ASP Nuke 0.80 - SQL Injection via TaskID Parameter
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.
by Alberto Trivero
CVE-2005-2067 EXPLOITDB perl VERIFIED
asp-nuke - SQL Injection via article.asp articleid Parameter
SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.
by mh_p0rtal
CVE-2005-2083 EXPLOITDB perl VERIFIED
IA eMailServer Corporate Edition 5.2.2 build 1051 - Denial of Service via IMAP4 LIST Command Format String
Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.
by Reed Arvin
CVE-2005-2075 EXPLOITDB perl VERIFIED
PHP-Fusion 5.0 and 6.0 - Unprotected Database File Exposure via Predictable Filename
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.
by Easyex
CVE-2005-2071 EXPLOITDB perl VERIFIED
Solaris 10 - Local Privilege Escalation via Traceroute Argument Handling
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).
by Przemyslaw Frasunek
EIP-2026-113490 EXPLOITDB perl VERIFIED
WordPress Core 1.5.1.1 - SQL Injection
by Alberto Trivero
EIP-2026-105678 EXPLOITDB perl VERIFIED
Cacti 0.8.6d - Remote Command Execution
by Alberto Trivero
EIP-2026-104675 EXPLOITDB perl VERIFIED
phpBB 2.0.15 - Register Multiple Users (Denial of Service)
by g30rg3_x