Aggregator
绕过 WebShell 检测的新思路,通过 Sharp4Error 运行时报错执行命令
8 months 2 weeks ago
.NET 内网攻防实战电子报刊
8 months 2 weeks ago
01.NET内网安全攻防报刊小报童电子报刊【.NET内网安全攻防】也正式上线了,引入小报童也是为了弥补知识星球
.NET 四种方法上传 web.config 绕过限制实现RCE
8 months 2 weeks ago
绕过 WebShell 检测的新思路,通过 Sharp4Error 运行时报错执行命令
8 months 2 weeks ago
.NET 内网攻防实战电子报刊
8 months 2 weeks ago
01.NET内网安全攻防报刊小报童电子报刊【.NET内网安全攻防】也正式上线了,引入小报童也是为了弥补知识星球
.NET 四种方法上传 web.config 绕过限制实现RCE
8 months 2 weeks ago
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 2 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 2 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 2 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 2 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 2 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
小米:雷军SU7事故公众信系伪造;任天堂官宣Switch 2,3400元;OpenAI发AI Agent评测基准 | 极客早知道
8 months 2 weeks ago
乐道总裁艾铁成离职;抖音回应「张一鸣已加入新加坡国籍」消息不实;Gartner 预计 2025 年 AI 支出将达到 6440 亿美元
CVE-2023-22630 | IzyBat Orange Casiers prior 20221102_1 getCasier.php taille sql injection (GHSA-j94f-5cg6-6j9j)
8 months 2 weeks ago
A vulnerability classified as critical was found in IzyBat Orange Casiers. This vulnerability affects unknown code of the file getCasier.php. The manipulation of the argument taille leads to sql injection.
This vulnerability was named CVE-2023-22630. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-23560 | Lexmark Product up to 2023-01-12 server-side request forgery
8 months 2 weeks ago
A vulnerability was found in Lexmark Product up to 2023-01-12. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2023-23560. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2022-31706 | VMware vRealize Log Insight path traversal (VMSA-2023-0001)
8 months 2 weeks ago
A vulnerability classified as critical has been found in VMware vRealize Log Insight. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2022-31706. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-31704 | VMware vRealize Log Insight access control (VMSA-2023-0001)
8 months 2 weeks ago
A vulnerability classified as critical was found in VMware vRealize Log Insight. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2022-31704. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-18329 | Rehau Device Configuration Interface permissions
8 months 2 weeks ago
A vulnerability was found in Rehau Device. It has been declared as very critical. This vulnerability affects unknown code of the component Configuration Interface. The manipulation leads to preservation of permissions.
This vulnerability was named CVE-2020-18329. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2022-20235 | Google Android PowerVR GPU Kernel Driver memory corruption (A-259967780)
8 months 2 weeks ago
A vulnerability classified as critical has been found in Google Android. Affected is an unknown function of the component PowerVR GPU Kernel Driver. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2022-20235. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-20458 | Google Android 12.0 CarNotificationListener.java StatusBarNotification.getKey log file (A-205567776)
8 months 2 weeks ago
A vulnerability was found in Google Android 12.0. It has been declared as problematic. Affected by this vulnerability is the function StatusBarNotification.getKey of the file CarNotificationListener.java. The manipulation leads to sensitive information in log files.
This vulnerability is known as CVE-2022-20458. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com