Aggregator
BlackStone: Pentesting Reporting Tool
3 months ago
BlackStone Project BlackStone project or “BlackStone Project” is a tool created in order to automate the work of drafting and submitting a report on audits of ethical hacking or pentesting. In this tool we...
The post BlackStone: Pentesting Reporting Tool appeared first on Penetration Testing Tools.
ddos
CVE-2004-1620 | S9y Serendipity up to 0.7 Beta4 index.php cross-site request forgery (EDB-24697 / Nessus ID 15543)
3 months ago
A vulnerability was found in S9y Serendipity and classified as problematic. Affected by this issue is some unknown functionality of the file index.php. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2004-1620. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
抖音整治高考「AI押题」视频;小米SU7 Ultra登陆《GT赛车7》;全球首个,满级QQ收获「金企鹅」 | 极客早知道
3 months ago
黄仁勋将于下周宣布德国最大的「AI 工厂」;SpaceX 成功发射 SiriusXM 无线电卫星;亚马逊正加速布局人形机器人
CVE-2006-4625 | PHP up to 5.1.6 php.ini ini_restore memory corruption (EDB-28504 / Nessus ID 29375)
3 months ago
A vulnerability classified as critical has been found in PHP up to 5.1.6. Affected is the function ini_restore of the file php.ini. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2006-4625. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-2023 | IBM i Access 7.1 on Windows memory corruption (EDB-38751 / SBV-56245)
3 months ago
A vulnerability has been found in IBM i Access 7.1 on Windows and classified as problematic. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2015-2023. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
DetentionDodger: Unmasking Leaked Credentials & Their Organizational Impact
3 months ago
DetentionDodger is a tool designed to find users whose credentials have been leaked/compromised and the impact they have on the target. Install Local Installation To install, the only thing needed, is to install the...
The post DetentionDodger: Unmasking Leaked Credentials & Their Organizational Impact appeared first on Penetration Testing Tools.
ddos
CVE-2025-27913 | Passbolt API up to 4 HTTP Header Host less trusted source (EUVD-2025-7821)
3 months ago
A vulnerability was found in Passbolt API up to 4 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Header Handler. The manipulation of the argument Host leads to use of less trusted source.
This vulnerability is handled as CVE-2025-27913. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27914 | Zimbra Collaboration Suite 9.0/10.0/10.1 URL /h/rest Query cross site scripting (EUVD-2025-7822)
3 months ago
A vulnerability, which was classified as problematic, has been found in Zimbra Collaboration Suite 9.0/10.0/10.1. Affected by this issue is some unknown functionality of the file /h/rest of the component URL Handler. The manipulation of the argument Query leads to cross site scripting.
This vulnerability is handled as CVE-2025-27914. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27910 | tianti 2.3 Request /user/ajax/upd/status cross-site request forgery (Issue 39 / EUVD-2025-7818)
3 months ago
A vulnerability was found in tianti 2.3. It has been classified as problematic. Affected is an unknown function of the file /user/ajax/upd/status of the component Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2025-27910. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-27912 | Datalust Seq up to 2024.1.11146 cross-site request forgery (EUVD-2025-7820)
3 months ago
A vulnerability was found in Datalust Seq. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-27912. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27911 | Datalust Seq up to 2024.1.11146 resource consumption (EUVD-2025-7819)
3 months ago
A vulnerability classified as problematic has been found in Datalust Seq. Affected is an unknown function. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2025-27911. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
vLLM源码(V0)结构分析
3 months ago
Terenceli
CVE-2007-3265 | IBM WebSphere Application Server up to 6.1.0.7 cross site scripting (ID 87054 / XFDB-34905)
3 months ago
A vulnerability, which was classified as problematic, has been found in IBM WebSphere Application Server up to 6.1.0.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting.
This vulnerability is handled as CVE-2007-3265. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2007-3282 | Microsoft Office DataSourceControl memory corruption (EDB-4067 / ID 110061)
3 months ago
A vulnerability, which was classified as critical, has been found in Microsoft Office. Affected by this issue is some unknown functionality of the component DataSourceControl. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2007-3282. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2007-3302 | CA eTrust Intrusion Detection 1.4.1.13/1.4.5 ActiveX Control caller.dll Remote Code Execution (ID 115602 / XFDB-35565)
3 months ago
A vulnerability was found in CA eTrust Intrusion Detection 1.4.1.13/1.4.5. It has been classified as very critical. Affected is an unknown function in the library caller.dll of the component ActiveX Control. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2007-3302. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-3305 | Trillian 3.1.5.1 UTF-8 Newline heap-based overflow (VU#187033 / Nessus ID 25547)
3 months ago
A vulnerability classified as critical was found in Trillian 3.1.5.1. This vulnerability affects unknown code of the component UTF-8 Newline Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2007-3305. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-3316 | VLC Media Player format string (VU#200928 / Nessus ID 25695)
3 months ago
A vulnerability was found in VLC Media Player. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to format string.
This vulnerability is known as CVE-2007-3316. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-0865 | PunBB up to 1.2.10 User Account denial of service (EDB-1517 / XFDB-24837)
3 months ago
A vulnerability classified as problematic was found in PunBB. Affected by this vulnerability is an unknown functionality of the component User Account. The manipulation leads to denial of service.
This vulnerability is known as CVE-2006-0865. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2004-2158 | S9y Serendipity 0.7 Beta1 exit.php entry_id sql injection (EDB-561 / Nessus ID 14842)
3 months ago
A vulnerability has been found in S9y Serendipity 0.7 Beta1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file exit.php. The manipulation of the argument entry_id leads to sql injection.
This vulnerability is known as CVE-2004-2158. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com