Wind River VxWorks Integer Overflow VulnerabilityWind River VxWorks Integer Overflow Vulnerability
Release date:Updated on:Affected Systems:
Wind River Systems VxWorks 5.5-6.9.4.1
Description:
VxWorks is a real-time operating system widely
PHP 'php _ var_unserialize () 'function re-exploits the remote code execution vulnerability after it is releasedPHP 'php _ var_unserialize () 'function re-exploits the remote code execution vulnerability after it is released
Release date:Updated
FFmpeg decode_ihdr_chunk DoS Vulnerability (CVE-2015-6818)FFmpeg decode_ihdr_chunk DoS Vulnerability (CVE-2015-6818)
Release date:Updated on:Affected Systems:
FFmpeg FFmpeg
Description:
CVE (CAN) ID: CVE-2015-6818FFmpeg is a free software that
Attackers intrude into the Bugzilla to access undisclosed bugs.
Mozilla issued a warning that an attacker steals sensitive undisclosed vulnerabilities from its bug Tracking System Bugzilla and may exploit the vulnerability information to attack
PHP 'zend _ HASH_IF_FULL_DO_RESIZE () 're-exploits the memory corruption vulnerability after being releasedPHP 'zend _ HASH_IF_FULL_DO_RESIZE () 're-exploits the memory corruption vulnerability after being released
Release date:Updated on:Affected
Linux Kernel Local Denial of Service Vulnerability (CVE-2015-1350)Linux Kernel Local Denial of Service Vulnerability (CVE-2015-1350)
Release date:Updated on:Affected Systems:
Linux kernel
Description:
Bugtraq id: 76075CVE (CAN) ID: CVE-2015-13
Second wave of ASP. NET Website intrusion
1. upload code page I uploaded the ashx page.
2. Use the text on the ashx page to display the web. Config content to get the database connection,
3. Use ashx to output the vbs script in the root directory of
Yisaitong data leakage protection system SQL Injection Vulnerability (no DBA permission required)
SQL Injection exists on the WAP logon page of the DLP System (no DBA permission required)
POST /CDGServer3/3g/LoginAction HTTP/1.1Host: 116.213.17
Javascript Cache Poisoning learning and practice
0x00 cause
Not long ago, I bought a wooyun wifi and talked about Cache Poisoning:
Then we can see the description of wooyun wifi:
By default, this function comes with the cache poisoning function.
ThinkPHP webshell skills
Someone on 90sec asked, I said there are still some tips that can't be used. I noticed when I audited TP last year. I simply analyzed the code and operation process.
The I function of thinkphp is the function for processing
CTF organizer's guide against zombies
0x00 background
XDCTF2015 is a CTF that I think is very powerful. The problem is moderately difficult and there is nothing wrong with it. It has ended successfully.
CTF has always been easy to get confused.
SQL injection vulnerability in tianrongxin Server Load balancer
SQL injection vulnerability in tianrongxin Server Load balancer
The command execution has been completed, and two SQLite injection vulnerabilities are proposed without logon.
This
Multiple linked payment servers have the Arbitrary File Upload Vulnerability (getshell)
Multiple linked payment servers have the Arbitrary File Upload Vulnerability (getshell)
1. http://weixin.allinpay.com/
Uploaded
The execution is successful,
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.