最新发布第954页
CVE-2022-29303: SolarView Compact 6.00 – OS Command Injection
漏洞标题 CVE-2022-29303: SolarView Compact 6.00 - OS Command Injection 漏洞描述 SolarView Compact 6.00 was discovered to contain a command injection vulnerability via conf_mail.php...
CVE-2023-4166-2: 通达OA seal_manage SQL 注入
漏洞标题 CVE-2023-4166-2: 通达OA seal_manage SQL 注入 漏洞描述 该漏洞影响文件general/system/seal_manage/dianju/delete_log.php的未知代码。对参数 DELETE_STR 的操作会导致 sql 注入。 P...
CVE-2023-30150: PrestaShop leocustomajax 1.0 & 1.0.0 – SQL Injection
漏洞标题 CVE-2023-30150: PrestaShop leocustomajax 1.0 & 1.0.0 - SQL Injection 漏洞描述 PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocus...
CVE-2017-9506: Atlassian Jira IconURIServlet – Cross-Site Scripting/Server-Side Request Forgery
漏洞标题 CVE-2017-9506: Atlassian Jira IconURIServlet - Cross-Site Scripting/Server-Side Request Forgery 漏洞描述 The Atlassian Jira IconUriServlet of the OAuth Plugin from version...
CVE-2022-45835: WordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request Forgery
漏洞标题 CVE-2022-45835: WordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request Forgery 漏洞描述 WordPress PhonePe Payment Solutions plugin through 1.0.15 is suscept...
CVE-2024-57045: D-Link DIR-859 – Information Disclosure
漏洞标题 CVE-2024-57045: D-Link DIR-859 - Information Disclosure 漏洞描述 A critical information disclosure vulnerability exists in D-Link devices where sensitive device account in...
CVE-2021-27320: Doctor Appointment System 1.0 – SQL Injection
漏洞标题 CVE-2021-27320: Doctor Appointment System 1.0 - SQL Injection 漏洞描述 Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated atta...
CVE-2021-25033: Noptin < 1.6.5 - Open Redirect
漏洞标题 CVE-2021-25033: Noptin < 1.6.5 - Open Redirect 漏洞描述 Noptin < 1.6.5 is susceptible to an open redirect vulnerability. The plugin does not validate the "to&qu...
CVE-2020-8615: WordPress Plugin Tutor LMS 1.5.3 – Cross-Site Request Forgery
漏洞标题 CVE-2020-8615: Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery 漏洞描述 A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in...
PDF解析器html/XSS 实现SSRF
上次安全小天地审核整理SSRF的时候找我沟通,聊到了PDF的SSRF,当时答应了找找之前的存档写个文档。遂写下改小菜文。大佬们勿喷。(文章写于去年,随便记录的文章,可能存在逻辑或者图片的丢失...
CVE-2011-5265: Featurific For WordPress 1.6.2 – Cross-Site Scripting
漏洞标题 CVE-2011-5265: Featurific For WordPress 1.6.2 - Cross-Site Scripting 漏洞描述 A cross-site scripting vulnerability in cached_image.php in the Featurific For WordPress plug...
CVE-2023-39677: PrestaShop MyPrestaModules – PhpInfo Disclosure
漏洞标题 CVE-2023-39677: PrestaShop MyPrestaModules - PhpInfo Disclosure 漏洞描述 PrestaShop modules by MyPrestaModules expose PHPInfo PoC代码
bugbounty技巧聚合20220121
漏洞报告 【 TikTok】跨站脚本 (XSS) - 存储在 ads.tiktok.com 的文本字段中 http://hackerone.com/reports/1376961 【 Shopify】存储在 http://linkpop.com 的 XSS http://hackerone.com/repor...
CVE-2010-0985: Joomla! Component com_abbrev – Local File Inclusion
漏洞标题 CVE-2010-0985: Joomla! Component com_abbrev - Local File Inclusion 漏洞描述 A directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for...
一次不会代码的代码审计
前言 由于小程序的便捷性,越来越多的应用迁移到了了小程序上,由此伴随着小程序上线前的日常渗透测试工作也开始增加。但小程序的测试中经常会遇到数据包被加密了,导致无法进行改包测试。和测...
CVE-2011-0762: vsftpd < 2.3.3 - DoS
漏洞标题 CVE-2011-0762: vsftpd < 2.3.3 - DoS 漏洞描述 The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial ...








