最新发布第526页
CVE-2024-22024: Ivanti Connect Secure – XXE
漏洞标题 CVE-2024-22024: Ivanti Connect Secure - XXE 漏洞描述 Ivanti Connect Secure is vulnerable to XXE (XML External Entity) injection. PoC代码
CVE-2010-1313: Joomla! Component Saber Cart 1.0.0.12 – Local File Inclusion
漏洞标题 CVE-2010-1313: Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion 漏洞描述 A directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0....
CVE-2025-10211: ChanCMS <= 3.3.0 - Server-Side Request Forgery
漏洞标题 CVE-2025-10211: ChanCMS <= 3.3.0 - Server-Side Request Forgery 漏洞描述 yanyutao0402 ChanCMS 3.3.0 contains a server-side request forgery caused by manipulation of the ...
CVE-2019-2725: Oracle WebLogic Remote Code Execution
漏洞标题 CVE-2019-2725: Oracle WebLogic Remote Code Execution 漏洞描述 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services...
CVE-2020-16139: Cisco Unified IP Conference Station 7937G – Denial-of-Service
漏洞标题 CVE-2020-16139: Cisco Unified IP Conference Station 7937G - Denial-of-Service 漏洞描述 Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers t...
(CVE-2025-52472) XWiki REST搜索URL HQL注入漏洞(orderField参数)
漏洞标题 (CVE-2025-52472) XWiki REST搜索URL HQL注入漏洞(orderField参数) 漏洞描述 (CVE-2025-52472) XWiki REST搜索URL HQL注入漏洞(orderField参数) PoC代码 暂无
CVE-2023-6379: OpenCMS 14 & 15 – Cross Site Scripting
漏洞标题 CVE-2023-6379: OpenCMS 14 & 15 - Cross Site Scripting 漏洞描述 Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of t...
CVE-2017-14186: FortiGate FortiOS SSL VPN Web Portal – Cross-Site Scripting
漏洞标题 CVE-2017-14186: FortiGate FortiOS SSL VPN Web Portal - Cross-Site Scripting 漏洞描述 FortiGate FortiOS through SSL VPN Web Portal contains a cross-site scripting vulnerabi...
CVE-2024-3094: XZ – Embedded Malicious Code
漏洞标题 CVE-2024-3094: XZ - Embedded Malicious Code 漏洞描述 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex...
CVE-2019-3799: Spring Cloud Config Server – Local File Inclusion
漏洞标题 CVE-2019-3799: Spring Cloud Config Server - Local File Inclusion 漏洞描述 Spring Cloud Config Server versions 2.1.x prior to 2.1.2, 2.0.x prior to 2.0.4, 1.4.x prior to 1....
一次奇葩的任意用户登录
在安全小天地测试某src时发现一个界面,域名为xxxa.xxx.com,是一个登录界面,发现该界面支持使用手机号登录以及注册功能,测试后发现该网站使用的短信验证码为123456 因此用脚趾头都能想出来的...
CVE-2017-18518: SMTP by BestWebSoft < 1.1.0 - Cross-Site Scripting
漏洞标题 CVE-2017-18518: SMTP by BestWebSoft < 1.1.0 - Cross-Site Scripting 漏洞描述 The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues. PoC代码
寻找python开启web服务中的宝藏
测试过程中,有时需要临时用python开启web服务,默认是允许目录浏览的,如果不及时关闭进程,可能会被窃取当前目录中的文件。 fofa(也可以尝试添加python2的服务器版本): ((server='SimpleHTTP/...
Apache Struts2(S2-001)远程代码执行漏洞(CVE-2007-4556)
漏洞标题 Apache Struts2(S2-001)远程代码执行漏洞(CVE-2007-4556) 漏洞描述 在Struts2 WebWork 2.1+ 和 Struts 2 的“altSyntax”功能允许将 OGNL表达式插入到文本字符串中并进行递归处理。这...
CVE-2017-18557: Google Maps by BestWebSoft < 1.3.6 - Cross-Site Scripting
漏洞标题 CVE-2017-18557: Google Maps by BestWebSoft < 1.3.6 - Cross-Site Scripting 漏洞描述 The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues. PoC代...
bugbounty技巧聚合20220209
漏洞报告 简单改ID越权250$ http://hackerone.com/reports/1124974 TikTok XSS 6000$ http://hackerone.com/reports/1452375 CVE-2022-21703,grafana跨站请求伪造(CSRF) http://jub0bs.com/pos...








