Aggregator
最新黑产技术曝光,只需19分钟即可劫持AI大模型
BigAnt Server 0-day Vulnerability Let Attackers Execute Malicious Code Via File Uploads
A critical zero-day vulnerability in BigAntSoft’s BigAnt Server (CVE-2025-0364) allows unauthenticated attackers to execute arbitrary code on affected systems through a chain of SaaS registration abuses and PHP file uploads. The flaw, discovered by VulnCheck researchers during an analysis of a misrated CVSS score for CVE-2024-54761, impacts all versions ≤5.6.06 of the Windows-based enterprise chat […]
The post BigAnt Server 0-day Vulnerability Let Attackers Execute Malicious Code Via File Uploads appeared first on Cyber Security News.
信息安全漏洞月报(2025年2月)
信息安全漏洞月报(2025年2月)
BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely
A critical vulnerability in BigAntSoft’s enterprise chat server software has exposed ~50 internet-facing systems to unauthenticated remote code execution attacks. Designated CVE-2025-0364, this exploit chain enables attackers to bypass authentication protocols, create administrative accounts, and execute malicious PHP code on vulnerable servers running BigAnt Server v5.6.06 and earlier. CVE-2025-0364: Authentication Bypass to PHP Code Execution The […]
The post BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.