Aggregator
.NET 2025 年第 80 期实战工具库和资源汇总
5 months ago
适配哥斯拉的 PNG WebShell,.NET 借助图片绕过安全拦截实现目标权限维持
5 months ago
【资料】美军作战行动系列操作手册
5 months ago
今天给大家分享100多篇美军作战行动相关的资料。
Coverage: A Python-based tool for analyzing Active Directory security
5 months ago
Domain Coverage Analysis Tool Tool for analyzing domain security based on various data sources: LDAP domain dump NTDS.dit dump Hashcat output List modules uv run main.py -l Available modules: – reversible_encryption – passwords_reuse –...
The post Coverage: A Python-based tool for analyzing Active Directory security appeared first on Penetration Testing Tools.
ddos
Intigriti teams with NVIDIA to launch bug bounty and vulnerability disclosure program (VDP)
5 months ago
NVIDIA与Intigriti社区合作,利用12.5万名道德黑客测试关键AI基础设施,并推出新计划加快安全问题的发现和响应。未来六个月内将启动漏洞赏金、漏洞披露等项目。
工业安全六步骤,助力化纤企业数字化转型升级
5 months ago
提前规划,分步实施,保障企业生产连续性、稳定性。
CVE-2025-7544 | Tenda AC1206 15.03.06.23 /goform/setMacFilterCfg formSetMacFilterCfg deviceList stack-based overflow (EUVD-2025-21279)
5 months ago
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-7544. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7547 | Campcodes Online Movie Theater Seat Reservation System 1.0 /admin/admin_class.php save_movie cover unrestricted upload (EUVD-2025-21275)
5 months ago
A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function save_movie of the file /admin/admin_class.php. The manipulation of the argument cover leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-7547. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7543 | PHPGurukul User Registration & Login and User Management System /admin/manage-users.php sql injection (EUVD-2025-21270)
5 months ago
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-7543. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7548 | Tenda FH1201 1.2.0.14(408) /goform/SafeEmailFilter formSafeEmailFilter page stack-based overflow
5 months ago
A vulnerability has been found in Tenda FH1201 1.2.0.14(408) and classified as critical. This vulnerability affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability was named CVE-2025-7548. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7549 | Tenda FH1201 1.2.0.14(408) /goform/L7Prot frmL7ProtForm page stack-based overflow
5 months ago
A vulnerability was found in Tenda FH1201 1.2.0.14(408) and classified as critical. This issue affects the function frmL7ProtForm of the file /goform/L7Prot. The manipulation of the argument page leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-7549. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7550 | Tenda FH1201 1.2.0.14(408) /goform/GstDhcpSetSer fromGstDhcpSetSer dips stack-based overflow
5 months ago
A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been classified as critical. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argument dips leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-7550. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
渗透测试0day漏洞归属与外包源代码安全责任探讨。|总第293周
5 months ago
本期周报简介:1、渗透测试发现的0day漏洞,厂商称属个人资产拒绝透露详情。法律及合同上如何界定漏洞归属与责任?
2、驻场外包人员用个人电脑编写的企业源代码未交付前泄露,依据法律和合同,如何确定责任方并采取何种预防措施?
CVE-2003-1313 | EternalMart Mailing List Manager 1.32 admin/auth.php emml_admin_path/emml_path privileges management (EDB-23218 / ID 11413)
5 months ago
A vulnerability classified as critical was found in EternalMart Mailing List Manager 1.32. Affected by this vulnerability is an unknown functionality of the file admin/auth.php. The manipulation of the argument emml_admin_path/emml_path leads to improper privilege management.
This vulnerability is known as CVE-2003-1313. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-1317 | eNdonesia 8.2 mod.php mod cross site scripting (EDB-23067 / ID 11393)
5 months ago
A vulnerability was found in eNdonesia 8.2 and classified as problematic. This issue affects some unknown processing of the file mod.php. The manipulation of the argument mod leads to basic cross site scripting.
The identification of this vulnerability is CVE-2003-1317. The attack may be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
vuldb.com
CVE-2003-1327 | wu-ftpd up to 2.6.3 Email SockPrintf memory corruption (Nessus ID 18726 / ID 27275)
5 months ago
A vulnerability classified as critical was found in wu-ftpd up to 2.6.3. This vulnerability affects the function SockPrintf of the component Email Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2003-1327. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
CVE-2003-1322 | Atrium Mercur Mailserver up to 4.2.14.x stack-based overflow (ID 50073 / XFDB-12203)
5 months ago
A vulnerability classified as critical was found in Atrium Mercur Mailserver up to 4.2.14.x. This vulnerability affects unknown code. The manipulation of the argument EXAMINE/DELETE/SUBSCRIBE/RENAME/UNSUBSCRIBE/LIST/LSUB/STATUS/LOGIN/CREATE/SELECT leads to stack-based buffer overflow.
This vulnerability was named CVE-2003-1322. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2003-1331 | Sun MySQL up to 4.0.13 libmysqlclient mysql_real_connect stack-based overflow (Nessus ID 17822 / ID 19674)
5 months ago
A vulnerability was found in Sun MySQL up to 4.0.13. It has been declared as critical. This vulnerability affects the function mysql_real_connect in the library libmysqlclient. The manipulation leads to stack-based buffer overflow.
This vulnerability was named CVE-2003-1331. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2003-1335 | Kai Blankenhorn Bitfolge Simple And Nice Index File up to 1.2.4 path traversal (ID 11457)
5 months ago
A vulnerability classified as critical was found in Kai Blankenhorn Bitfolge Simple And Nice Index File up to 1.2.4. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal.
This vulnerability is known as CVE-2003-1335. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com