VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-200805-0160 CVE-2008-2005
WonderWare SuiteLink 2.0 - Remote Denial of Service (Metasploit) - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200805-0133
EDB ID: 6474
WonderWare SuiteLink 2.0 - Remote Denial of Service (Metasploit). CVE-2008-2005CVE-44801 . dos exploit for Windows platform
VAR-E-200803-0750 CVE-2008-1150
CVE-2008-1151
Cisco IOS Virtual Private Dial-up Network Multiple Denial of Service Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-200803-0326, VAR-200803-0327
No EDB ID
Cisco IOS is prone to multiple denial-of-service vulnerabilities that occur in the virtual private dial-up (VPDN) when the Point-to-Point Tunneling Protocol (PPTP) is enabled. Successfully exploiting these issues may cause a memory leak or prevent the establishment of VPDN connections, denying service to legitimate users.
VAR-E-200803-0265 CVE-2008-1152
Cisco IOS Multiple DLSw Denial of Service Vulnerablities

Related entries in the VARIoT vulnerabilities database: VAR-200803-0328
No EDB ID
Cisco IOS is prone to multiple remote denial-of-service vulnerabilities because the software fails to properly handle malformed network datagrams. Successfully exploiting these issues allows remote attackers to trigger memory leaks or crashes in targeted devices. This will lead to denial-of-service conditions. These issues are tracked by Cisco Bug ID CSCsk73104.
VAR-E-200803-0228 CVE-2006-5202
CVE-2008-1247
Linksys WRT54G Firmware 1.00.9 - Security Bypass (2) - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200803-0170, VAR-200610-0506
EDB ID: 5926
Linksys WRT54G Firmware 1.00.9 - Security Bypass (2). CVE-2006-5202CVE-27808CVE-27807 . remote exploit for Hardware platform
VAR-E-200803-0463 CVE-2008-0306
SAP MaxDB sdbstarter Environment Variable Local Privilege Escalation Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200803-0281
No EDB ID
SAP MaxDB is prone to a local privilege-escalation vulnerability. Exploiting this issue allows local attackers to execute arbitrary code with superuser privileges. This will lead to the complete compromise of an affected computer. This issue affects MaxDB 7.6.0.37 on both Linux and Solaris platforms. Other UNIX variants are most likely affected. Microsoft Windows versions are not vulnerable to this issue.
VAR-E-200803-0227 CVE-2008-1247
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1) - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200803-0170
EDB ID: 5313
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1). CVE-2008-1247 . remote exploit for Hardware platform
VAR-E-200803-0399 CVE-2008-0539
F5 BIG-IP 9.4.3 - Web Management Interface Console HTML Injection - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200802-0048
EDB ID: 31364
F5 BIG-IP 9.4.3 - Web Management Interface Console HTML Injection.. remote exploit for Hardware platform
VAR-E-200802-0592 CVE-2007-6258
Apache Tomcat Connector jk2-2.0.2 mod_jk2 - Remote Overflow - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200802-0064
EDB ID: 5386
Apache Tomcat Connector jk2-2.0.2 mod_jk2 - Remote Overflow. CVE-2007-6258 . remote exploit for Linux platform
VAR-E-200802-0133 CVE-2008-7032
F5 BIG-IP 9.4.3 - Web Management Interface Cross-Site Request Forgery - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200908-0116
EDB ID: 31133
F5 BIG-IP 9.4.3 - Web Management Interface Cross-Site Request Forgery. CVE-2008-7032CVE-50985 . remote exploit for Hardware platform
VAR-E-200802-0400 CVE-2008-0621
CVE-2008-0620
SapLPD 6.28 (Windows x86) - Remote Buffer Overflow - Windows_x86 remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200802-0423, VAR-200802-0422
EDB ID: 5079
SapLPD 6.28 (Windows x86) - Remote Buffer Overflow. CVE-2008-0621 . remote exploit for Windows_x86 platform
VAR-E-200802-0399 CVE-2008-0621
CVE-2008-0620
SapLPD 6.28 - Remote Buffer Overflow (Metasploit) - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200802-0423, VAR-200802-0422
EDB ID: 16338
SapLPD 6.28 - Remote Buffer Overflow (Metasploit). CVE-2008-0621CVE-41127 . remote exploit for Windows platform
VAR-E-200801-0039 CVE-2008-0565
CVE-2008-6720
DELTAScripts PHP Links - Multiple SQL Injections - PHP webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200904-0147, VAR-200802-0354
EDB ID: 37786
DELTAScripts PHP Links - Multiple SQL Injections. CVE-2008-6720CVE-2008-0565CVE-53672CVE-41145CVE-126494CVE-126493CVE-126492CVE-126491CVE-126490 . webapps exploit for PHP platform
VAR-E-200801-0244 CVE-2008-0566
PHP Links 1.3 - 'smarty.php' Remote File Inclusion - PHP webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200802-0355
EDB ID: 5022
PHP Links 1.3 - 'smarty.php' Remote File Inclusion. CVE-41144CVE-2008-0566 . webapps exploit for PHP platform
VAR-E-200801-0040 CVE-2008-0565
PHP Links 1.3 - 'id' SQL Injection - PHP webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200802-0354
EDB ID: 5021
PHP Links 1.3 - 'id' SQL Injection. CVE-41145CVE-2008-0565CVE-40840 . webapps exploit for PHP platform
VAR-E-200801-0428 CVE-2008-0406
CVE-2008-0409
CVE-2008-0410
CVE-2008-0405
CVE-2008-0407
CVE-2008-0408
Rejetto HTTP File Server (HFS) 1.5/2.x - Multiple Vulnerabilities - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200801-0091, VAR-200801-0094, VAR-200801-0092, VAR-200801-0095, VAR-200801-0096, VAR-200801-0093
EDB ID: 31056
Rejetto HTTP File Server (HFS) 1.5/2.x - Multiple Vulnerabilities. CVE-2008-0406CVE-42509 . remote exploit for Windows platform
VAR-E-200801-0321 CVE-2008-0337
CVE-2008-0338
Miniweb 0.8.19 - Multiple Vulnerabilities - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200801-0319, VAR-200801-0318
EDB ID: 4923
Miniweb 0.8.19 - Multiple Vulnerabilities. CVE-42781CVE-2008-0338CVE-42780CVE-2008-0337 . remote exploit for Windows platform
VAR-E-200801-0221 CVE-2008-0265
F5 BIG-IP 9.4.3 - 'SearchString' Multiple Cross-Site Scripting Vulnerabilities - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200801-0243
EDB ID: 31024
F5 BIG-IP 9.4.3 - 'SearchString' Multiple Cross-Site Scripting Vulnerabilities. CVE-2008-0265CVE-40345 . remote exploit for Hardware platform
VAR-E-200801-0306 CVE-2008-0244
SAP MaxDB 7.6.03.07 - Remote Command Execution - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200801-0222
EDB ID: 4877
SAP MaxDB 7.6.03.07 - Remote Command Execution. CVE-40210CVE-2008-0244 . remote exploit for Multiple platform
VAR-E-200801-0050 CVE-2008-0220
CVE-2008-0221
Gateway Weblaunch - ActiveX Control Insecure Method - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200801-0366, VAR-200801-0367
EDB ID: 4869
Gateway Weblaunch - ActiveX Control Insecure Method. CVE-41653CVE-2008-0221CVE-41652CVE-2008-0220 . remote exploit for Windows platform
VAR-E-200801-0049 CVE-2008-0220
Gateway WebLaunch - ActiveX Remote Buffer Overflow - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200801-0366
EDB ID: 4982
Gateway WebLaunch - ActiveX Remote Buffer Overflow. CVE-2008-0220 . remote exploit for Windows platform