云记-渗透云记 - 专注于网络安全与技术分享-第818页
CVE-2020-26413: Gitlab CE/EE 13.4 - 13.6.2 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2020-26413: Gitlab CE/EE 13.4 – 13.6.2 – Information Disclosure

漏洞标题 CVE-2020-26413: Gitlab CE/EE 13.4 - 13.6.2 - Information Disclosure 漏洞描述 GitLab CE and EE 13.4 through 13.6.2 is susceptible to Information disclosure via GraphQL. Use...
CVE-2022-0786: WordPress KiviCare <2.3.9 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-0786: WordPress KiviCare <2.3.9 - SQL Injection

漏洞标题 CVE-2022-0786: WordPress KiviCare <2.3.9 - SQL Injection 漏洞描述 WordPress KiviCare plugin before 2.3.9 contains a SQL injection vulnerability. The plugin does not san...
CVE-2023-2766: Weaver OA 9.5 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2023-2766: Weaver OA 9.5 – Information Disclosure

漏洞标题 CVE-2023-2766: Weaver OA 9.5 - Information Disclosure 漏洞描述 A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown pr...
xxe快速验证-渗透云记 - 专注于网络安全与技术分享

xxe快速验证

有回显,用以下poc直接读取/etc/passwd: <?xml version='1.0'?> <!DOCTYPE foo [ <!ELEMENT foo (#ANY)> <!ENTITY xxe SYSTEM 'file:///etc/passwd'>]><foo>&am...
2022年3月10日 23:37
010
CVE-2018-9845: Etherpad Lite <1.6.4 - Admin Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2018-9845: Etherpad Lite <1.6.4 - Admin Authentication Bypass

漏洞标题 CVE-2018-9845: Etherpad Lite <1.6.4 - Admin Authentication Bypass 漏洞描述 Etherpad Lite before 1.6.4 is exploitable for admin access. PoC代码
CVE-2010-1308: Joomla! Component SVMap 1.1.1 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2010-1308: Joomla! Component SVMap 1.1.1 – Local File Inclusion

漏洞标题 CVE-2010-1308: Joomla! Component SVMap 1.1.1 - Local File Inclusion 漏洞描述 A directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allow...
CVE-2021-46422: SDT-CW3B1 1.1.0 - OS Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-46422: SDT-CW3B1 1.1.0 – OS Command Injection

漏洞标题 CVE-2021-46422: SDT-CW3B1 1.1.0 - OS Command Injection 漏洞描述 Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attack...
CVE-2010-1715: Joomla! Component Online Exam 1.5.0 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2010-1715: Joomla! Component Online Exam 1.5.0 – Local File Inclusion

漏洞标题 CVE-2010-1715: Joomla! Component Online Exam 1.5.0 - Local File Inclusion 漏洞描述 A directory traversal vulnerability in the Online Examination (aka Online Exam or com_on...
CVE-2023-0876: WordPress Meta SEO <= 4.5.2 - Open Redirect-渗透云记 - 专注于网络安全与技术分享

CVE-2023-0876: WordPress Meta SEO <= 4.5.2 - Open Redirect

漏洞标题 CVE-2023-0876: WordPress Meta SEO <= 4.5.2 - Open Redirect 漏洞描述 The WP Meta SEO WordPress plugin before 4.5.3 did not authorize several AJAX actions, which allowed ...
CVE-2023-29887: Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2023-29887: Nuovo Spreadsheet Reader 0.5.11 – Local File Inclusion

漏洞标题 CVE-2023-29887: Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion 漏洞描述 A Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote...
CVE-2024-34102: Adobe Commerce & Magento - CosmicSting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-34102: Adobe Commerce & Magento – CosmicSting

漏洞标题 CVE-2024-34102: Adobe Commerce & Magento - CosmicSting 漏洞描述 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Res...
充分利用互联网资源的小tips-续集-渗透云记 - 专注于网络安全与技术分享

充分利用互联网资源的小tips-续集

挖掘src的时候找到一个资产如下 正常测试弱口令,未授权接口等无果 通过fofa搜索指纹,发现是一个通用的cms 把站点都薅下来,然后尝试弱口令,成功进入后台,顺便发现了一个这个后台的通用默认...
2022年3月10日 23:39
010
CVE-2010-5028: Joomla! Component JE Job 1.0 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2010-5028: Joomla! Component JE Job 1.0 – Local File Inclusion

漏洞标题 CVE-2010-5028: Joomla! Component JE Job 1.0 - Local File Inclusion 漏洞描述 A SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! a...
CVE-2023-38992: Jeecg-Boot v3.5.1 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-38992: Jeecg-Boot v3.5.1 – SQL Injection

漏洞标题 CVE-2023-38992: Jeecg-Boot v3.5.1 - SQL Injection 漏洞描述 SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData in jeecg-boot v3.5.1. PoC代码
(CVE-2022-0954) Microweber 权限控制不当漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2022-0954) Microweber 权限控制不当漏洞

漏洞标题 (CVE-2022-0954) Microweber 权限控制不当漏洞 漏洞描述 (CVE-2022-0954) Microweber 权限控制不当漏洞 PoC代码 暂无
linux下RPM包安装基于xinetd的服务的管理_Linux-渗透云记 - 专注于网络安全与技术分享

linux下RPM包安装基于xinetd的服务的管理_Linux

目录前言1、基于xinetd服务的启动管理(1)telnet服务安装(2)telnet服务启动2、基于xientd服务的自启动管理前言 现在Linux系统中基于xinetd的服务越来越少了,但Linux系统中还是有基于xinetd...
2022年6月15日 08:45
010