Aggregator
【资料】美军作战行动系列操作手册
6 days 14 hours ago
今天给大家分享100多篇美军作战行动相关的资料。
Coverage: A Python-based tool for analyzing Active Directory security
6 days 15 hours ago
Domain Coverage Analysis Tool Tool for analyzing domain security based on various data sources: LDAP domain dump NTDS.dit dump Hashcat output List modules uv run main.py -l Available modules: – reversible_encryption – passwords_reuse –...
The post Coverage: A Python-based tool for analyzing Active Directory security appeared first on Penetration Testing Tools.
ddos
Intigriti teams with NVIDIA to launch bug bounty and vulnerability disclosure program (VDP)
6 days 15 hours ago
NVIDIA与Intigriti社区合作,利用12.5万名道德黑客测试关键AI基础设施,并推出新计划加快安全问题的发现和响应。未来六个月内将启动漏洞赏金、漏洞披露等项目。
工业安全六步骤,助力化纤企业数字化转型升级
6 days 15 hours ago
提前规划,分步实施,保障企业生产连续性、稳定性。
CVE-2025-6491 | PHP SOAP Extension null pointer dereference (EUVD-2025-21276 / Nessus ID 242042)
6 days 15 hours ago
A vulnerability has been found in PHP and classified as problematic. This vulnerability affects unknown code of the component SOAP Extension. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2025-6491. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-7544 | Tenda AC1206 15.03.06.23 /goform/setMacFilterCfg formSetMacFilterCfg deviceList stack-based overflow (EUVD-2025-21279)
6 days 15 hours ago
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-7544. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7545 | GNU Binutils 2.45 binutils/objcopy.c copy_section heap-based overflow (Bug 33049 / EUVD-2025-21278)
6 days 15 hours ago
A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2025-7545. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-7546 | GNU Binutils 2.45 bfd/elf.c bfd_elf_set_group_contents out-of-bounds write (Bug 33050 / EUVD-2025-21277)
6 days 15 hours ago
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2025-7546. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-1735 | PHP pgsql Extension null pointer dereference (EUVD-2025-21273 / Nessus ID 242042)
6 days 15 hours ago
A vulnerability, which was classified as problematic, was found in PHP. This affects an unknown part of the component pgsql Extension. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-1735. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-7547 | Campcodes Online Movie Theater Seat Reservation System 1.0 /admin/admin_class.php save_movie cover unrestricted upload (EUVD-2025-21275)
6 days 15 hours ago
A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function save_movie of the file /admin/admin_class.php. The manipulation of the argument cover leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-7547. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7543 | PHPGurukul User Registration & Login and User Management System /admin/manage-users.php sql injection (EUVD-2025-21270)
6 days 15 hours ago
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-7543. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7548 | Tenda FH1201 1.2.0.14(408) /goform/SafeEmailFilter formSafeEmailFilter page stack-based overflow
6 days 15 hours ago
A vulnerability has been found in Tenda FH1201 1.2.0.14(408) and classified as critical. This vulnerability affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability was named CVE-2025-7548. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7549 | Tenda FH1201 1.2.0.14(408) /goform/L7Prot frmL7ProtForm page stack-based overflow
6 days 15 hours ago
A vulnerability was found in Tenda FH1201 1.2.0.14(408) and classified as critical. This issue affects the function frmL7ProtForm of the file /goform/L7Prot. The manipulation of the argument page leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-7549. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7550 | Tenda FH1201 1.2.0.14(408) /goform/GstDhcpSetSer fromGstDhcpSetSer dips stack-based overflow
6 days 15 hours ago
A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been classified as critical. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argument dips leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-7550. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
渗透测试0day漏洞归属与外包源代码安全责任探讨。|总第293周
6 days 15 hours ago
本期周报简介:1、渗透测试发现的0day漏洞,厂商称属个人资产拒绝透露详情。法律及合同上如何界定漏洞归属与责任?
2、驻场外包人员用个人电脑编写的企业源代码未交付前泄露,依据法律和合同,如何确定责任方并采取何种预防措施?
CVE-2003-1313 | EternalMart Mailing List Manager 1.32 admin/auth.php emml_admin_path/emml_path privileges management (EDB-23218 / ID 11413)
6 days 15 hours ago
A vulnerability classified as critical was found in EternalMart Mailing List Manager 1.32. Affected by this vulnerability is an unknown functionality of the file admin/auth.php. The manipulation of the argument emml_admin_path/emml_path leads to improper privilege management.
This vulnerability is known as CVE-2003-1313. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-1317 | eNdonesia 8.2 mod.php mod cross site scripting (EDB-23067 / ID 11393)
6 days 15 hours ago
A vulnerability was found in eNdonesia 8.2 and classified as problematic. This issue affects some unknown processing of the file mod.php. The manipulation of the argument mod leads to basic cross site scripting.
The identification of this vulnerability is CVE-2003-1317. The attack may be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
vuldb.com
CVE-2003-1327 | wu-ftpd up to 2.6.3 Email SockPrintf memory corruption (Nessus ID 18726 / ID 27275)
6 days 15 hours ago
A vulnerability classified as critical was found in wu-ftpd up to 2.6.3. This vulnerability affects the function SockPrintf of the component Email Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2003-1327. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2003-1322 | Atrium Mercur Mailserver up to 4.2.14.x stack-based overflow (ID 50073 / XFDB-12203)
6 days 15 hours ago
A vulnerability classified as critical was found in Atrium Mercur Mailserver up to 4.2.14.x. This vulnerability affects unknown code. The manipulation of the argument EXAMINE/DELETE/SUBSCRIBE/RENAME/UNSUBSCRIBE/LIST/LSUB/STATUS/LOGIN/CREATE/SELECT leads to stack-based buffer overflow.
This vulnerability was named CVE-2003-1322. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com