Aggregator
.NET 安全攻防知识交流社区
8 months 3 weeks ago
BlackStone: Pentesting Reporting Tool
8 months 3 weeks ago
BlackStone Project BlackStone project or “BlackStone Project” is a tool created in order to automate the work of drafting and submitting a report on audits of ethical hacking or pentesting. In this tool we...
The post BlackStone: Pentesting Reporting Tool appeared first on Penetration Testing Tools.
ddos
CVE-2004-1620 | S9y Serendipity up to 0.7 Beta4 index.php cross-site request forgery (EDB-24697 / Nessus ID 15543)
8 months 3 weeks ago
A vulnerability was found in S9y Serendipity and classified as problematic. Affected by this issue is some unknown functionality of the file index.php. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2004-1620. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
抖音整治高考「AI押题」视频;小米SU7 Ultra登陆《GT赛车7》;全球首个,满级QQ收获「金企鹅」 | 极客早知道
8 months 3 weeks ago
黄仁勋将于下周宣布德国最大的「AI 工厂」;SpaceX 成功发射 SiriusXM 无线电卫星;亚马逊正加速布局人形机器人
CVE-2006-4625 | PHP up to 5.1.6 php.ini ini_restore memory corruption (EDB-28504 / Nessus ID 29375)
8 months 3 weeks ago
A vulnerability classified as critical has been found in PHP up to 5.1.6. Affected is the function ini_restore of the file php.ini. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2006-4625. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-2023 | IBM i Access 7.1 on Windows memory corruption (EDB-38751 / SBV-56245)
8 months 3 weeks ago
A vulnerability has been found in IBM i Access 7.1 on Windows and classified as problematic. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2015-2023. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
DetentionDodger: Unmasking Leaked Credentials & Their Organizational Impact
8 months 3 weeks ago
DetentionDodger is a tool designed to find users whose credentials have been leaked/compromised and the impact they have on the target. Install Local Installation To install, the only thing needed, is to install the...
The post DetentionDodger: Unmasking Leaked Credentials & Their Organizational Impact appeared first on Penetration Testing Tools.
ddos
CVE-2025-27913 | Passbolt API up to 4 HTTP Header Host less trusted source (EUVD-2025-7821)
8 months 3 weeks ago
A vulnerability was found in Passbolt API up to 4 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Header Handler. The manipulation of the argument Host leads to use of less trusted source.
This vulnerability is handled as CVE-2025-27913. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27914 | Zimbra Collaboration Suite 9.0/10.0/10.1 URL /h/rest Query cross site scripting (EUVD-2025-7822)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Zimbra Collaboration Suite 9.0/10.0/10.1. Affected by this issue is some unknown functionality of the file /h/rest of the component URL Handler. The manipulation of the argument Query leads to cross site scripting.
This vulnerability is handled as CVE-2025-27914. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27910 | tianti 2.3 Request /user/ajax/upd/status cross-site request forgery (Issue 39 / EUVD-2025-7818)
8 months 3 weeks ago
A vulnerability was found in tianti 2.3. It has been classified as problematic. Affected is an unknown function of the file /user/ajax/upd/status of the component Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-27910. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
vLLM源码(V0)结构分析
8 months 3 weeks ago
Terenceli
CVE-2007-3265 | IBM WebSphere Application Server up to 6.1.0.7 cross site scripting (ID 87054 / XFDB-34905)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in IBM WebSphere Application Server up to 6.1.0.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting.
This vulnerability is handled as CVE-2007-3265. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2007-3282 | Microsoft Office DataSourceControl memory corruption (EDB-4067 / ID 110061)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Microsoft Office. Affected by this issue is some unknown functionality of the component DataSourceControl. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2007-3282. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-3302 | CA eTrust Intrusion Detection 1.4.1.13/1.4.5 ActiveX Control caller.dll Remote Code Execution (ID 115602 / XFDB-35565)
8 months 3 weeks ago
A vulnerability was found in CA eTrust Intrusion Detection 1.4.1.13/1.4.5. It has been classified as very critical. Affected is an unknown function in the library caller.dll of the component ActiveX Control. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2007-3302. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-3305 | Trillian 3.1.5.1 UTF-8 Newline heap-based overflow (VU#187033 / Nessus ID 25547)
8 months 3 weeks ago
A vulnerability classified as critical was found in Trillian 3.1.5.1. This vulnerability affects unknown code of the component UTF-8 Newline Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2007-3305. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-3316 | VLC Media Player format string (VU#200928 / Nessus ID 25695)
8 months 3 weeks ago
A vulnerability was found in VLC Media Player. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to format string.
This vulnerability is known as CVE-2007-3316. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-0865 | PunBB up to 1.2.10 User Account denial of service (EDB-1517 / XFDB-24837)
8 months 3 weeks ago
A vulnerability classified as problematic was found in PunBB. Affected by this vulnerability is an unknown functionality of the component User Account. The manipulation leads to denial of service.
This vulnerability is known as CVE-2006-0865. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2004-2158 | S9y Serendipity 0.7 Beta1 exit.php entry_id sql injection (EDB-561 / Nessus ID 14842)
8 months 3 weeks ago
A vulnerability has been found in S9y Serendipity 0.7 Beta1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file exit.php. The manipulation of the argument entry_id leads to sql injection.
This vulnerability is known as CVE-2004-2158. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-1889 | BuddyPress plugin up to 1.9.1 on WordPress Group Creation access control (EDB-31571 / ID 12847)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in BuddyPress plugin up to 1.9.1 on WordPress. This issue affects some unknown processing of the component Group Creation Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2014-1889. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com