云记-渗透云记 - 专注于网络安全与技术分享-第243页
CVE-2022-28666: Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update-渗透云记 - 专注于网络安全与技术分享

CVE-2022-28666: Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update

漏洞标题 CVE-2022-28666: Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update 漏洞描述 YIKES Inc. Custom Product Tabs for WooCommerce plug...
Atlassian Jira 信息泄露(CVE-2019-3401)-渗透云记 - 专注于网络安全与技术分享

Atlassian Jira 信息泄露(CVE-2019-3401)

漏洞标题 Atlassian Jira 信息泄露(CVE-2019-3401) 漏洞描述 Jira 7.13.3之前版本和8.1.1之前版本8.0.0中的ManageFilters.jspa资源允许远程攻击者通过不正确的授权检查枚举用户名。 PoC代码 暂...
CVE-2021-39350: FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-39350: FV Flowplayer Video Player WordPress plugin – Authenticated Cross-Site Scripting

漏洞标题 CVE-2021-39350: FV Flowplayer Video Player WordPress plugin - Authenticated Cross-Site Scripting 漏洞描述 The FV Flowplayer Video Player WordPress plugin is vulnerable to ...
CVE-2019-1003000: Jenkins Script Security Plugin <=1.49 - Sandbox Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2019-1003000: Jenkins Script Security Plugin <=1.49 - Sandbox Bypass

漏洞标题 CVE-2019-1003000: Jenkins Script Security Plugin <=1.49 - Sandbox Bypass 漏洞描述 A sandbox bypass vulnerability exists in the Jenkins Script Security Plugin (versions ...
CVE-2020-26217: XStream <1.4.14 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2020-26217: XStream <1.4.14 - Remote Code Execution

漏洞标题 CVE-2020-26217: XStream <1.4.14 - Remote Code Execution 漏洞描述 XStream before 1.4.14 is susceptible to remote code execution. An attacker can run arbitrary shell comm...
CVE-2018-7314: Joomla! Component PrayerCenter 3.0.2 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2018-7314: Joomla! Component PrayerCenter 3.0.2 – SQL Injection

漏洞标题 CVE-2018-7314: Joomla! Component PrayerCenter 3.0.2 - SQL Injection 漏洞描述 SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid paramet...
CVE-2023-29357: Microsoft SharePoint - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2023-29357: Microsoft SharePoint – Authentication Bypass

漏洞标题 CVE-2023-29357: Microsoft SharePoint - Authentication Bypass 漏洞描述 Microsoft SharePoint Server Elevation of Privilege Vulnerability PoC代码
nginx优化的六点方法_nginx-渗透云记 - 专注于网络安全与技术分享

nginx优化的六点方法_nginx

这篇文章主要介绍了nginx优化的六点方法,有对nginx优化不太熟悉的同学可以参考下 一.优化Nginx并发量 [root@proxy ~]# ab -n 2000 -c 2000 http://192.168.4.5/ Benchmarking 192.168.4.5 (be p...
2022年10月12日 21:35
030
CVE-2010-0219: Apache Axis2 Default Login-渗透云记 - 专注于网络安全与技术分享

CVE-2010-0219: Apache Axis2 Default Login

漏洞标题 CVE-2010-0219: Apache Axis2 Default Login 漏洞描述 Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products...
CVE-2020-27982: IceWarp WebMail 11.4.5.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2020-27982: IceWarp WebMail 11.4.5.0 – Cross-Site Scripting

漏洞标题 CVE-2020-27982: IceWarp WebMail 11.4.5.0 - Cross-Site Scripting 漏洞描述 IceWarp WebMail 11.4.5.0 is vulnerable to cross-site scripting via the language parameter. PoC代码
CVE-2017-5521: Bypassing Authentication on NETGEAR Routers-渗透云记 - 专注于网络安全与技术分享

CVE-2017-5521: Bypassing Authentication on NETGEAR Routers

漏洞标题 CVE-2017-5521: Bypassing Authentication on NETGEAR Routers 漏洞描述 NETGEAR routers before 6.0.10 allow remote attackers to bypass authentication and gain access to the ro...
(CVE-2020-1956) Apache Kylin RESTful API 命令注入漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2020-1956) Apache Kylin RESTful API 命令注入漏洞

漏洞标题 (CVE-2020-1956) Apache Kylin RESTful API 命令注入漏洞 漏洞描述 (CVE-2020-1956) Apache Kylin RESTful API 命令注入漏洞 PoC代码 暂无
CVE-2024-0250: Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect-渗透云记 - 专注于网络安全与技术分享

CVE-2024-0250: Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect

漏洞标题 CVE-2024-0250: Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect 漏洞描述 The plugin is vulnerable to Open Redirect due to insufficient validation on the ...
CVE-2021-25296: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-25296: Nagios XI 5.5.6-5.7.5 – Authenticated Remote Command Injection

漏洞标题 CVE-2021-25296: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection 漏洞描述 Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command inject...
CVE-2023-22478: KubePi <= v1.6.4 LoginLogsSearch - Unauthorized Access-渗透云记 - 专注于网络安全与技术分享

CVE-2023-22478: KubePi <= v1.6.4 LoginLogsSearch - Unauthorized Access

漏洞标题 CVE-2023-22478: KubePi <= v1.6.4 LoginLogsSearch - Unauthorized Access 漏洞描述 KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and m...
CVE-2025-32433: Erlang/OTP SSH - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-32433: Erlang/OTP SSH – Remote Code Execution

漏洞标题 CVE-2025-32433: Erlang/OTP SSH - Remote Code Execution 漏洞描述 Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26....