Aggregator
Phishing links
CVE-2024-2138 | JetWidgets for Elementor Plugin up to 1.0.15 on WordPress Animated Box Widget cross site scripting (ID 3050010)
CVE-2024-2226 | Otter Block Plugin up to 2.6.4 on WordPress cross site scripting (ID 3050429)
CVE-2024-2325 | Link Library Plugin up to 7.6.6 on WordPress cross site scripting (ID 3050134)
CVE-2024-1813 | Simple Job Board Plugin up to 2.11.0 on WordPress Job Application Form code injection
CVE-2024-2341 | Appointment Booking Calendar Plugin up to 1.6.7.7 on WordPress sql injection
CVE-2024-2340 | Avada Plugin up to 7.11.6 on WordPress information disclosure
CVE-2024-2342 | Appointment Booking Calendar Plugin up to 1.6.7.7 on WordPress Shortcode sql injection
CVE-2024-3423 | SourceCodester Online Courseware 1.0 admin/activateteach.php selector sql injection
CVE-2024-1991 | metagauss RegistrationMagic Plugin up to 5.3.0.0 on WordPress update_users_role authorization (ID 3049490)
CVE-2004-1018 | PHP up to 4.3.10/5.0.3 shmop_write privileges management (EDB-24854 / Nessus ID 18091)
Qilin
Cloud AuthoriZation Trainer: A simulator of cloud-provider responsible REST APIs
CAZT (Cloud AuthoriZation Trainer) CAZT (Cloud AuthoriZation Trainer) is a simulator of cloud-provider responsible REST APIs. It includes a lab manual for getting hands-on practice with how to attack authorization vulnerabilities in a cloud...
The post Cloud AuthoriZation Trainer: A simulator of cloud-provider responsible REST APIs appeared first on Penetration Testing Tools.
ISC Stormcast For Friday, January 31st, 2025 https://isc.sans.edu/podcastdetail/9304, (Fri, Jan 31st)
patching: Interactive Binary Patching Plugin for IDA Pro
Patching – Interactive Binary Patching for IDA Pro Patching assembly code to change the behavior of an existing program is not uncommon in malware analysis, software reverse engineering, and broader domains of security research....
The post patching: Interactive Binary Patching Plugin for IDA Pro appeared first on Penetration Testing Tools.
CVE-2007-2353 | Apache Axis 1.0 Installation javaioFileNotFoundException information disclosure (EDB-29930 / XFDB-34167)
PEnetration TEsting Proxy: open-source Java application for traffic analysis & modification
PEnetration TEsting Proxy PETEP (PEnetration TEsting Proxy) is an open-source Java application for creating proxies for traffic analysis & modification. The main goal of PETEP is to provide a useful tool for performing penetration tests...
The post PEnetration TEsting Proxy: open-source Java application for traffic analysis & modification appeared first on Penetration Testing Tools.