Aggregator
CVE-2024-39665 | YMC Filter & Grids Plugin up to 2.9.2 on WordPress cross site scripting
CVE-2024-39667 | BdThemes Element Pack Elementor Addons Plugin up to 5.6.11 on WordPress cross site scripting
CVE-2024-39663 | Epsiloncool WP Fast Total Search Plugin up to 1.68.232 on WordPress cross site scripting
CVE-2024-39636 | CodeSolz Better Find and Replace Plugin up to 1.6.1 on WordPress deserialization
CVE-2024-39668 | petesheppard84 Extensions for Elementor Plugin up to 2.0.31 on WordPress cross site scripting
CVE-2013-1765 | smart-flv jwplayer.swf playerready cross site scripting (EDB-38331 / BID-58135)
CVE-2012-5386 | Nicolas Tormo phpPaleo 4.8b180 index.php path traversal (EDB-18701 / SA48398)
GraphStrike: Cobalt Strike HTTPS beaconing over Microsoft Graph API
GraphStrike GraphStrike is a suite of tools that enables Cobalt Strike’s HTTPS Beacon to use Microsoft Graph API for C2 communications. All Beacon traffic will be transmitted via two files created in the attacker’s SharePoint site,...
The post GraphStrike: Cobalt Strike HTTPS beaconing over Microsoft Graph API appeared first on Penetration Testing Tools.
CVE-2010-3206 | DiY-CMS 1.0 control.block.php getFile code injection (EDB-14822 / XFDB-61454)
DakshSCRA: Source Code Review Assist
Daksh SCRA (Source Code Review Assist) Daksh SCRA (Source Code Review Assist) tool is built to enhance the efficiency of the source code review process, providing a well-structured and organized approach for code reviewers....
The post DakshSCRA: Source Code Review Assist appeared first on Penetration Testing Tools.
HBSQLI: Automated Tool for Testing Header Based Blind SQL Injection
HBSQLI: Automated Tester For Header-Based Blind SQL Injection HBSQLI is an automated command-line tool for performing Header Based Blind SQL injection attacks on web applications. It automates the process of detecting Header Based Blind...
The post HBSQLI: Automated Tool for Testing Header Based Blind SQL Injection appeared first on Penetration Testing Tools.