WordPress in the blog Security Series

Let's talk about Wordpress security today ..WORDPRESS has been very insecure recently. 0-day vulnerabilities often exist ~ Therefore, you need to set the security of the program.========================================================== =============

Database explosion and repair of enterprise website Systems

From: www.0855. TVBy: Mr. DzYDate: 2011/08/25 The enterprise website system is a small-sized enterprise website source code customized for small and medium-sized enterprises. The code is made public for free and can be modified and learned on its

MiaCMS v4.9.0 Multiple Remote File Inclusion Defects and repair

Title: MiaCMS v4.9.0 Multiple Remote File compression sion VulnerabilitiesAuthor: KedAns-Dz www.2cto.com# E-mail: ked-h@hotmail.com (ked-h@1337day.com) | ked-h@exploit-id.com | kedans@facebook.comPlatform: phpLevel: Remote File/Sh3lL compression

40-bit MD5 Encryption

Now I want to talk about the 40-bit Decryption Method to everyone about the 40-bit encrypted data. In fact, it is still MD5 encryption, but some changes have been made:Take admin as an example,Admin's 16-bit and 32-bit ciphertext:7a57a5a743894a0e2123

ET speech cross-site scripting vulnerability and repair

Author mog Brief description:Cross-site scripting (XSS) attacks exist in ET voice software. The account password can be obtained through simulated login.Detailed description:When a custom video is played in a channel, the webpage is

DotProject 2.1.5 SQL Injection defects and repair

Title: dotProject 2.1.5 SQL Injection Vulnerability Author: sherl0ck _ @ AlligatorTeam Developer Website: http://www.dotproject.net/ Tested version 2.1.5 Test Platform: Debian GNU/Linux 5.0 Example: URL: Http://www.bkjia.com/dotproject/index. php?

WordPress plugin WP e-Commerce & lt; = 3.8.6 SQL Injection defects and repair

Title: WordPress WP e-Commerce plugin Author: Miroslav Stampar (miroslav. stampar (at) gmail.com @ stamparm) Software: http://downloads.wordpress.org/plugin/wp-e-commerce.3.8.6.zip Tested version: 3.8.6 Annotation: parameter $ _ POST ["cs3"] = md5

How to crack the prompt in the enterprise website registration version

Recently, we used a template for the zhirui enterprise website. (This template is downloaded from all major websites and marked as free use and free software.) I feel that the framework architecture is clear and simple, the most important version is

Kuwebs 0-day and repair

Error_reporting (E_ERROR );Print_r ('+ --------------------------------------------------------------------- +Kuwebs cms SQL injection expHome: www.hkmjj.com www.2cto.com+ --------------------------------------------------------------------- +'); If

Feed on Feeds & lt; = 0.5 remote code injection defects and repair

    /* ------------------------------------------------------ Feed on Feeds ------------------------------------------------------ Author ......: EgiX Mail ......: n0b0d13s [at] gmail [dot] com www.2cto.com Software link...:

Cotonti CMS v0.9.4 Multiple Remote defects and repair

  Title: Cotonti CMS v0.9.4 Multiple Remote Vulnerabilities Author: Cotonti Team www.2cto.com Developer: http://www.cotonti.com Affected Versions: 0.9.4 (Siena) Summary: Cotonti is a powerful open-source web development   Framework and content

WP-SpamFree WordPress Spam plug-in SQL Injection defects and repair

Title: [WordPress wpsf-js plugin, SQL Injection]Author: [cheki] www.2cto.comAffected Versions: [3.2.1]Test Platform: [linux]Tool: ["sqlmap"]# SQL InjectionHttp://www.bkjia.com/wp-content/plugins/wp-spamfree/JavaScript/wpsf-js.php? Id = 1 Test: id =-1

Use the system time to predict and crack java random numbers

Abstract:This is a classic example of random function cracking. In java programs, there are multiple methods to obtain random numbers. However, when we implement a random token and use it for authentication, we usually think of using "System.

Contao 2.10.1 cross-site scripting defects and repair

  By Stefan Schurtz www.2cto.com Affected program: Successfully tested on Contao 2.10.1 Developer Website: http://www.contao.org/ Official Patch: fixed   Overview ======================================   Contao 2.10 contains multiple css

JqueryUpload large File Upload Arbitrary File Upload Vulnerability and repair

  1. directly access default. aspx after the directory is guessed (you may need to modify the uploadid parameter. You can see the specific packet capture, but undefined is not allowed)   2. Upload and test, capture packets   3. Modify the

Xss of localStorage on twitter

Author: nerd does not speak   Brief description: It's very funny, but I can give you an xss after using your computer. Detailed description: Know the id of the target user. Execute js www.2cto.com in the current domain. LocalStorage. setItem ("

LibrettoCMS 2.2.2 Arbitrary File Upload

# Title: LibrettoCMS 2.2.2 Malicious File Upload # discoverer: CWH Underground # Official Website: http://libretto.artwebonline.com/ #: http://jaist.dl.sourceforge.net/project/librettocms/librettoCMS_v.2.2.2.zip # Affected versions: 2.2.2 # Test

An unauthorized access from a system in Sohu leads to arbitrary command execution.

It is mainly because a system is authorized to access the database, resulting in the execution of arbitrary commands, the permission is still root, the database is not subject to access restrictions, and the data volume is quite large ..Details:

XSS + CSRF provides detailed analysis and Breakthrough measures for ACFUN users' persistent hijacking and self-propagation.

User center friend group location: X "x =" x There is a length check on the page, but it doesn't matter. packet capture structure: Name = addGroup & groupName = x "onmouseover =" var h = document. getElementsByTagName ('head') [0]; var s =

Sogou main site domxss

A long time ago I found that I have been researching and trying to release it. It is also good for the manufacturer to fix it early. When I first discovered it, I could only use it to play a box, and I could not even write a jump. Go directly to the

Total Pages: 1330 1 .... 813 814 815 816 817 .... 1330 Go to: GO

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.