最新发布第285页
CVE-2025-4302: Stop User Enumeration WordPress plugin – Authentication Bypass
漏洞标题 CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass 漏洞描述 Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass ...
CVE-2023-40749: PHPJabbers Food Delivery Script v3.0 – SQL Injection
漏洞标题 CVE-2023-40749: PHPJabbers Food Delivery Script v3.0 - SQL Injection 漏洞描述 PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column"...
CVE-2022-31181: PrestaShop – SQL Injection to Eval Injection
漏洞标题 CVE-2022-31181: PrestaShop - SQL Injection to Eval Injection 漏洞描述 PrestaShop versions from 1.6.0.10 and before 1.7.8.7 contain an SQL injection caused by unsanitized u...
Win10下配置IIS10并支持调试ASP程序的步骤_win服务器
今天临时需要在Win10下配置IIS10并支持调试ASP程序的步骤,不像windows服务器版本比较好找,这个得找到放风,这里九尾大家分享一下需要的朋友可以参考下 微软公司的IIS IIS(Internet Informatio...
CVE-2024-28734: Coda v.2024Q1 – Cross-Site Scripting
漏洞标题 CVE-2024-28734: Coda v.2024Q1 - Cross-Site Scripting 漏洞描述 Cross Site Scripting vulnerability in Unit4 Financials by Coda v.2024Q1 allows a remote attacker to escalate ...
CVE-2018-2893: Oracle WebLogic Server – Remote Code Execution
漏洞标题 CVE-2018-2893: Oracle WebLogic Server - Remote Code Execution 漏洞描述 The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versio...
CVE-2023-2059: DedeCMS 5.7.87 – Directory Traversal
漏洞标题 CVE-2023-2059: DedeCMS 5.7.87 - Directory Traversal 漏洞描述 Directory traversal vulnerability in DedeCMS 5.7.87 allows reading sensitive files via the $activepath paramet...
CVE-2023-27639: PrestaShop TshirteCommerce – Directory Traversal
漏洞标题 CVE-2023-27639: PrestaShop TshirteCommerce - Directory Traversal 漏洞描述 The Custom Product Designer (tshirtecommerce) module for PrestaShop allows HTTP requests to be fo...
CVE-2010-1531: Joomla! Component redSHOP 1.0 – Local File Inclusion
漏洞标题 CVE-2010-1531: Joomla! Component redSHOP 1.0 - Local File Inclusion 漏洞描述 A directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! a...
CVE-2023-24278: Squidex <7.4.0 - Cross-Site Scripting
漏洞标题 CVE-2023-24278: Squidex <7.4.0 - Cross-Site Scripting 漏洞描述 Squidex before 7.4.0 contains a cross-site scripting vulnerability via the squid.svg endpoint. An attacke...
CVE-2015-9499: WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Upload to RCE
漏洞标题 CVE-2015-9499: WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Upload to RCE 漏洞描述 The WordPress ShowBiz Pro plugin version <= 1.7.1 allows arbitrar...
CVE-2024-27564: ChatGPT个人专用版 – Server Side Request Forgery
漏洞标题 CVE-2024-27564: ChatGPT个人专用版 - Server Side Request Forgery 漏洞描述 A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attacker...
CVE-2018-10736: Nagios XI SQL Inject
漏洞标题 CVE-2018-10736: Nagios XI SQL Inject 漏洞描述 Nagios XI SQL Inject PoC代码
渗透测试中凭据获取之浏览器
作者:Mac.Asure原文地址:http://paper.seebug.org/3152/ 1. 前言 本文介绍提取三种常见浏览器Password和Cookie的原理以及关键代码实现,测试版本为最新版浏览器。 2. 凭据获取 -- Password 通...
CVE-2014-4561: Ultimate Weather Plugin <= 1.0 - Cross-Site Scripting
漏洞标题 CVE-2014-4561: Ultimate Weather Plugin <= 1.0 - Cross-Site Scripting 漏洞描述 The ultimate-weather plugin 1.0 for WordPress contains a cross-site scripting vulnerabilit...
bugbounty技巧聚合20220211
漏洞报告 自动填充导致信息泄露1900$ http://hackerone.com/reports/1083922 垂直越权 800$ http://hackerone.com/reports/1392032 Spring Boot信息泄露 5000$ http://hackerone.com/reports/10...








