Aggregator
.NET 高级代码审计:一种绕过 GZip 叠加 BinaryFormatter 实现反序列化漏洞的技术
8 months ago
《.NET安全攻防指南》上下册,官方海报版重磅发布!
8 months ago
。
CVE-2025-32782 | team-alembic ash_authentication up to 4.6.x missing authentication (GHSA-3988-q8q7-p787)
8 months ago
A vulnerability, which was classified as critical, was found in team-alembic ash_authentication up to 4.6.x. Affected is an unknown function. The manipulation leads to missing authentication.
This vulnerability is traded as CVE-2025-32782. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
blutter: Flutter Mobile Application Reverse Engineering Tool
8 months ago
B(l)utter Flutter Mobile Application Reverse Engineering Tool by Compiling Dart AOT Runtime Currently, the application supports only Android libapp.so. Also, the application currently works only against recent Dart versions. Install This application uses the...
The post blutter: Flutter Mobile Application Reverse Engineering Tool appeared first on Penetration Testing Tools.
ddos
HuffLoader恶意软件技术分析
8 months ago
HuffLoader恶意软件技术分析
CVE-2023-43292 | My Food Recipe 1.0 Recipe Name/Procedure/ingredients cross site scripting
8 months ago
A vulnerability has been found in My Food Recipe 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Recipe Name/Procedure/ingredients leads to cross site scripting.
This vulnerability is known as CVE-2023-43292. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-28239 | Directus up to 10.9.x API GET Request google redirect (GHSA-fr3w-2p22-6w7p)
8 months ago
A vulnerability was found in Directus up to 10.9.x. It has been classified as problematic. This affects an unknown part of the file directus/auth/login/google of the component API GET Request Handler. The manipulation of the argument redirect leads to open redirect.
This vulnerability is uniquely identified as CVE-2024-28239. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23300 | Apple GarageBand up to 10.4.10 File use after free (HT214090)
8 months ago
A vulnerability classified as critical has been found in Apple GarageBand up to 10.4.10. Affected is an unknown function of the component File Handler. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-23300. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-42308 | code-projects Exam Form Submission 1.0 Manage Fastrack Subjects cross site scripting
8 months ago
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Manage Fastrack Subjects. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-42308. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1894 | Burst Statistics Plugin up to 1.5.6.1 on WordPress burst_total_pageviews_count cross site scripting
8 months ago
A vulnerability classified as problematic was found in Burst Statistics Plugin up to 1.5.6.1 on WordPress. This vulnerability affects unknown code. The manipulation of the argument burst_total_pageviews_count leads to cross site scripting.
This vulnerability was named CVE-2024-1894. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Supernova: shellcode encryption tool
8 months ago
Supernova Supernova is an open-source tool that empowers users to securely encrypt and/or obfuscate their raw shellcode.Supernova supports various features beyond those typically found in a common shellcode encryptor tool. Features Supernova offers automatic...
The post Supernova: shellcode encryption tool appeared first on Penetration Testing Tools.
ddos
Weekly Report: 複数のマイクロソフト製品に脆弱性
8 months ago
複数のマイクロソフト製品には、脆弱性があります。同社は、今回修正された一部の脆弱性を悪用する攻撃をすでに確認しているとのことです。この問題は、Microsoft Updateなどを用いて、更新プログラムを適用することで解決します。詳細は、開発者が提供する情報を参照してください。
[webapps] phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
8 months ago
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
[remote] Hugging Face Transformers MobileViTV2 4.41.1 - Remote Code Execution (RCE)
8 months ago
Hugging Face Transformers MobileViTV2 4.41.1 - Remote Code Execution (RCE)
[webapps] Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
8 months ago
Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
[webapps] NagVis 1.9.33 - Arbitrary File Read
8 months ago
NagVis 1.9.33 - Arbitrary File Read
[webapps] Zabbix 7.0.0 - SQL Injection
8 months ago
Zabbix 7.0.0 - SQL Injection
[hardware] ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF)
8 months ago
ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF)
[hardware] ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution
8 months ago
ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution