云记-渗透云记 - 专注于网络安全与技术分享-第857页
CVE-2024-36683: PrestaShop productsalert - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-36683: PrestaShop productsalert – SQL Injection

漏洞标题 CVE-2024-36683: PrestaShop productsalert - SQL Injection 漏洞描述 In the module 'Products Alert' (productsalert) up to version 1.7.4 from Smart Modules for Prest...
CVE-2021-25016: Chaty < 2.8.2 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-25016: Chaty < 2.8.2 - Cross-Site Scripting

漏洞标题 CVE-2021-25016: Chaty < 2.8.2 - Cross-Site Scripting 漏洞描述 The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and es...
CVE-2023-28121: WooCommerce Payments - Unauthorized Admin Access-渗透云记 - 专注于网络安全与技术分享

CVE-2023-28121: WooCommerce Payments – Unauthorized Admin Access

漏洞标题 CVE-2023-28121: WooCommerce Payments - Unauthorized Admin Access 漏洞描述 An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauth...
CVE-2022-23131_Zabbix登录绕过漏洞分析及复现-渗透云记 - 专注于网络安全与技术分享

CVE-2022-23131_Zabbix登录绕过漏洞分析及复现

前言 由于传播、利用此文所提供的信息而造成的任何直接或者间接的后果及损失,均由使用者本人负责,文章作者不为此承担任何责任。 本文章中的漏洞均为公开的漏洞收集,如果文章中的漏洞出现敏感...
2022年3月10日 23:37
010
CVE-2018-7700: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2018-7700: DedeCMS 5.7SP2 – Cross-Site Request Forgery/Remote Code Execution

漏洞标题 CVE-2018-7700: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution 漏洞描述 DedeCMS 5.7SP2 is susceptible to cross-site request forgery with a corresponding ...
bugbounty技巧聚合20220217-渗透云记 - 专注于网络安全与技术分享

bugbounty技巧聚合20220217

漏洞报告 Cookie不失效 http://hackerone.com/reports/948345 缺少 SPF 记录 http://hackerone.com/reports/1416701 挖洞技巧 Bypass WAF http://hadess.io/waf-bypass-methods/ 零点击账号接管...
2022年3月10日 23:34
010
CVE-2021-21972: VMware vSphere Client (HTML5) - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-21972: VMware vSphere Client (HTML5) – Remote Code Execution

漏洞标题 CVE-2021-21972: VMware vSphere Client (HTML5) - Remote Code Execution 漏洞描述 VMware vCenter vSphere Client (HTML5) contains a remote code execution vulnerability in a vC...
CVE-2021-30128: Apache OFBiz <17.12.07 - Arbitrary Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-30128: Apache OFBiz <17.12.07 - Arbitrary Code Execution

漏洞标题 CVE-2021-30128: Apache OFBiz <17.12.07 - Arbitrary Code Execution 漏洞描述 Apache OFBiz before 17.12.07 is susceptible to arbitrary code execution via unsafe deserializ...
CVE-2023-38992: Jeecg-Boot v3.5.1 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-38992: Jeecg-Boot v3.5.1 – SQL Injection

漏洞标题 CVE-2023-38992: Jeecg-Boot v3.5.1 - SQL Injection 漏洞描述 SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData in jeecg-boot v3.5.1. PoC代码
CVE-2021-25082: WordPress Popup Builder < 4.0.7 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-25082: WordPress Popup Builder < 4.0.7 - Remote Code Execution

漏洞标题 CVE-2021-25082: WordPress Popup Builder < 4.0.7 - Remote Code Execution 漏洞描述 Popup Builder WordPress plugin before 4.0.7 contains a local file inclusion caused by u...
CVE-2022-28290: WordPress Country Selector <1.6.6 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-28290: WordPress Country Selector <1.6.6 - Cross-Site Scripting

漏洞标题 CVE-2022-28290: WordPress Country Selector <1.6.6 - Cross-Site Scripting 漏洞描述 WordPress Country Selector plugin prior to 1.6.6 contains a cross-site scripting vulne...
CVE-2023-45136: XWiki < 14.10.14 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-45136: XWiki < 14.10.14 - Cross-Site Scripting

漏洞标题 CVE-2023-45136: XWiki < 14.10.14 - Cross-Site Scripting 漏洞描述 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it...
bugbounty技巧聚合20211202-渗透云记 - 专注于网络安全与技术分享

bugbounty技巧聚合20211202

漏洞报告 【VK.com】XSS http://hackerone.com/reports/1115763 【 VK.com】#1343280 Получаем название и аватарку (50x50) частной группы. http://ha...
2022年3月10日 23:33
010
CVE-2019-9082: ThinkPHP < 3.2.4 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2019-9082: ThinkPHP < 3.2.4 - Remote Code Execution

漏洞标题 CVE-2019-9082: ThinkPHP < 3.2.4 - Remote Code Execution 漏洞描述 ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Exec...
CVE-2024-34102: Adobe Commerce & Magento - CosmicSting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-34102: Adobe Commerce & Magento – CosmicSting

漏洞标题 CVE-2024-34102: Adobe Commerce & Magento - CosmicSting 漏洞描述 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Res...
CVE-2020-9496: Apache OFBiz 17.12.03 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2020-9496: Apache OFBiz 17.12.03 – Cross-Site Scripting

漏洞标题 CVE-2020-9496: Apache OFBiz 17.12.03 - Cross-Site Scripting 漏洞描述 Apache OFBiz 17.12.03 contains cross-site scripting and unsafe deserialization vulnerabilities via an ...