Aggregator
.NET 安全攻防知识交流社区
6 months 1 week ago
ViewState 演化简史,从结构性缺陷到触发RCE漏洞
6 months 1 week ago
.NET 安全攻防知识交流社区
6 months 1 week ago
当前环境出现异常问题,需完成验证操作后才能继续访问相关内容或功能。
ViewState 演化简史,从结构性缺陷到触发RCE漏洞
6 months 1 week ago
当前环境出现异常问题,需完成验证后才能继续访问相关内容或服务。
实战级权限维持,一键部署 ViewState WebShell
6 months 1 week ago
当前网络环境出现异常情况,需完成验证操作后方可继续访问相关内容。
使用不同工具对目标网站进行目录文件探测
6 months 1 week ago
本文介绍了使用Dirsearch、Gobuster和Dirbuster三款工具进行目录和文件探测的实验目的及原理,详细解析了Dirsearch的功能特性及其常用命令参数,并附有免责声明提醒读者谨慎使用技术信息并遵守相关法律法规。
evilgophish: Combination of evilginx2 and GoPhish
6 months 1 week ago
evilgophish Combination of evilginx2 and GoPhish. Why? As a penetration tester or red teamer, you may have heard of evilginx2 as a proxy man-in-the-middle framework capable of bypassing two-factor/multi-factor authentication. This is enticing to us, to say the...
The post evilgophish: Combination of evilginx2 and GoPhish appeared first on Penetration Testing Tools.
ddos
CVE-2012-10025 | Advanced Custom Fields Plugin up to 3.5.1 on WordPress POST Parameter core/actions/export.php acf_abspath filename control (EUVD-2012-6571 / EDB-23856)
6 months 1 week ago
A vulnerability was found in Advanced Custom Fields Plugin up to 3.5.1 on WordPress and classified as critical. This issue affects some unknown processing of the file core/actions/export.php of the component POST Parameter Handler. The manipulation of the argument acf_abspath leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2012-10025. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2012-10026 | Asset-Manager Plugin up to 2.0 on WordPress upload.php unrestricted upload (EUVD-2012-6570 / EDB-18993)
6 months 1 week ago
A vulnerability was found in Asset-Manager Plugin up to 2.0 on WordPress. It has been classified as critical. Affected is an unknown function of the file upload.php. The manipulation leads to unrestricted upload. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2012-10026. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-50592 | SeaCMS up to 13.1 player vid cross site scripting (EUVD-2025-23652)
6 months 1 week ago
A vulnerability was found in SeaCMS up to 13.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Upload/js/player/dmplayer/player. The manipulation of the argument vid leads to cross site scripting.
This vulnerability is handled as CVE-2025-50592. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52078 | Writebot AI Content Generator SaaS React Template up to 4.0.0 POST Request /file-upload unrestricted upload (EUVD-2025-23650)
6 months 1 week ago
A vulnerability classified as critical has been found in Writebot AI Content Generator SaaS React Template up to 4.0.0. Affected is an unknown function of the file /file-upload of the component POST Request Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2025-52078. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-7306 | Frontend File Manager Plugin up to 21.5 on WordPress wpfm_delete_multiple_files missing authentication (EUVD-2023-59765)
6 months 1 week ago
A vulnerability was found in Frontend File Manager Plugin up to 21.5 on WordPress and classified as critical. Affected by this issue is the function wpfm_delete_multiple_files. The manipulation leads to missing authentication.
This vulnerability is handled as CVE-2023-7306. The attack may be launched remotely. There is no exploit available.
vuldb.com
Grok + LinkedIn = 82 Interviews in a week [AMA]
6 months 1 week ago
作者毕业后发现求职过程充满问题如虚假职位和低效申请流程,于是创建Laboro平台实时抓取公司真实职位,并开发AI代理自动完成申请流程,完全免费使用。
OpenAI完成80亿美元融资,估值3000亿;宇树发布新一代机器狗;英伟达深夜发声:不存在后门、终止开关、监控软件|极客早知道
6 months 1 week ago
英伟达再度深夜发声:我们的芯片不存在后门、终止开关、监控软件;
阿里巴巴 2026 届秋招启动:预计发放超 7000 个 offer,AI 类岗位占比超 6 成;
特斯拉在英国和德国的销量暴跌超 55%,比亚迪则销量飙升
OpenAI完成80亿美元融资,估值3000亿;宇树发布新一代机器狗;英伟达深夜发声:不存在后门、终止开关、监控软件|极客早知道
6 months 1 week ago
当前环境出现异常问题,需完成验证后才能继续访问相关内容或功能。
Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover
6 months 1 week ago
Critical vulnerabilities discovered in the NVIDIA Triton Inference Server platform pose a significant threat to the security of AI infrastructure across both Windows and Linux environments. This concerns an open-source solution designed for large-scale...
The post Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover appeared first on Penetration Testing Tools.
ddos
Need help hooking SoundPool in Android game to restore broken sound effects (Puzzle Craft 2)
6 months 1 week ago
文章描述了用户因网络安全性问题被拦截的情况,并建议用户提交工单以解决误封问题。
Weekly Report: IPAが「2025年度 夏休みにおける情報セキュリティに関する注意喚起」を公開
6 months 1 week ago
独立行政法人情報処理推進機構(IPA)は、「2025年度 夏休みにおける情報セキュリティに関する注意喚起」を公開しました。長期休暇における、個人の利用者、企業や組織の利用者、企業や組織の管理者、それぞれの対象者に対して取るべき対策を説明しています。
CVE-2019-19043 | Linux Kernel up to 5.3.11 i40e_main.c i40e_setup_macvlans resource consumption (Nessus ID 243382)
6 months 1 week ago
A vulnerability was found in Linux Kernel up to 5.3.11. It has been classified as problematic. Affected is the function i40e_setup_macvlans of the file drivers/net/ethernet/intel/i40e/i40e_main.c. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2019-19043. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com