Vulndb

漏洞是在硬件、软件、协议的具体实现或系统安全策略上存在的缺陷,Exploit、Shellcode、PoC

WordPress 4.5.3 Core Ajax Handlers Path Traversal

Path traversal vulnerability in WordPress Core Ajax handlers ------------------------------------------------------------------------ Yorick Koster...

WordPress Count per Day Plugin 3.5.4 – Stored Cross-Site Scripting

EDB-ID: 40206 Author: Julien Rentrop CVE: N/A Published: 2016-08-05 Type: webapps Platform: PHP Stored Cross-Site Scripting vulnerability in Count ...

WordPress Gravity Forms 1.8.19 Shell Upload

WordPress Gravity Forms 1.8.19 Shell Upload

发布:2016.06.18 级别:高 CWE:CWE-264 <?php # Exploit Title: WordPress Gravity Forms - Arbitrary File Upload # Vendor Homepage: http://www.gravityforms.com/ # Vulnerable Version(s): 1.8.19...

Internet Explorer 11 VBScript Engine Memory Corruption

Internet Explorer 11 VBScript Engine Memory Corruption

发布:2016.08.06 级别:高 CVE:CVE-2016-0189 远程:是 ## # This module requires Metasploit: http://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## ...

WordPress Advanced Custom Fields: Table Field 1.1.12 XSS

WordPress Advanced Custom Fields: Table Field 1.1.12 XSS

Details ================ Software: Advanced Custom Fields: Table Field Version: 1.1.12 Homepage: https://wordpress.org/plugins/advanced-custom-fields-table-field/ Advisory report: https://security....

微擎科技最新版某处无需登录sql注入

微擎科技最新版某处无需登录sql注入

文件\payment\unionpay\notify.php <?php /**  * [WeEngine System] Copyright (c) 2014 WE7.CC  * WeEngine is NOT a free software, it under the license terms, visited http://www.we7.cc/ for more d...

wordpress 3.0-3.9.2 XSS Getshell Payload

如果实战用记得把 console.lnfo 那一行该为发送喔。。。 密码:fuckxssQ 这个getshell js 有getshell当前模板跟getshell全部模板的功能 默认是getshell当前模...

Discuz <= 7.2 SQL未公开注入漏洞

Discuz <= 7.2 SQL未公开注入漏洞

据说是某数字公司的应急给发布出来了.群里面的小伙伴都惊呆了 具体的漏洞分析看:http://www.80vul.com/webzine_0x06/PSTZine_0x06_0x03.txt 其中的 在《高级PHP应用程序漏洞审核技术》[1]一文里的"魔术引号带...

Siteserver 3.6.3版SQL注入漏洞

官方最新版本3.6.4。 扫描siteserver 3.6.3版本目录结构,获得URL如下 http://www/siteserver/CMS/console_tableMetadata.aspx?ENName=cms_Content&TableType...

Dede后台getshell【过20130715】

测试版本为:V5.7 20130715 测试步骤: 后台——SQL命令运器——执行命令 PgSQL INSERT INTO `dede_myad` (`aid`, `clsid`, `typeid`...