Posts
Gitlab Html Injection in file search
2024 Intigriti CTF, some Web solution
CVE-2024-39903: Local File Inclusion in Solara
Arbitrary File Overwrite in jupyter notebook
Zipslip when parsing invoice zip file via InvoiceOCRAssistant in metagpt
XSS in Siyuan Electron App when rendering mermaid block diagram Leading to RCE(Just Thanks)
XSS in Bluestone Electron App when rendering mermaid class diagram Leading to RCE(Just Thanks)
XSS in Outline when rendering mermaid diagrams(No Security Impact!)
Arbitrary File Overwrite via unstructured-ingest in unstructured(Just Thanks)
Remote Code Execution via Arbitrary File Overwrite Using Path Traversal in intel-extension-for-transformers neural_chat
Arbitrary File Deletion via Path Traversal in intel-extension-for-transformers neural_chat
Remote Code Execution via Arbitrary File Overwrite Using Path Traversal in langflow Pre-release(No Response)
Google: Local File Inclusion in FHIR Pipelines Controller
Hackerone: Store XSS in Gitness markdown comment editor
Google: Local File Inclusion in Turbinia API Server
Dev.to(Forem) cta xss(No Response,But Fixed!)
CVE-2024-32005: Local File Inclusion in NiceGUI leaflet component
Remote Code Execution via Arbitrary File Overwrite Using Path Traversal in agent-protocol
高危:有道智云存在微博OAuth2登录缺陷串联XSS漏洞实现账户劫持(忽略!)
CVE-2024-5187: Arbitrary File Overwrite in onnx
中危:网易灵犀企业邮箱存在存储型XSS漏洞
高危:网易云课堂ai设计工坊存在文件读取漏洞
中危:有道云笔记网页版思维导图存在存储型XSS漏洞
中危:有道云笔记网页版白板存在存储型XSS漏洞
中危:有道云笔记网页端渲染流程图存在存储型XSS漏洞
中危:有道云笔记markdown模式渲染类图(classDiagram)存储型XSS漏洞
Reproduction: Gitlab Arbitrary file read via the bulk imports UploadsPipeline
Reproduction: Gitlab Arbitrary file read via the UploadsRewriter when moving and issue
Gitlab debugging: Using gitlab official docker to debug rails backend
Reproduction: Gitlab Cross-site Scripting (XSS) - Stored in RDoc wiki pages
Reproduction: Gitlab Stored XSS in markdown when redacting references
Reproduction: Gitlab Stored XSS via Kroki diagram
Reproduction: Gitlab Stored-XSS with CSP-bypass via labels' color
Reproduction: Gitlab CSP-bypass XSS in project settings page
高危:网易大神手机客户端Webview mxss漏洞
中危:网易大神Web端频道签到消息存储型XSS漏洞
中危:网易大神Web端频道分享帖子存储型XSS漏洞
低危:网易UU论坛深井Web版评论等功能存在SSRF漏洞
中危(重复):网易UU论坛深井Web发帖和回复存储型XSS漏洞
中危:网易天工网站wordpress主题discy未授权访问
中危:网易数帆-codewave开发论坛未授权修改用户信息
中危:网易数帆-codewave开发论坛敏感信息泄露
高危:网易数帆codewave开发论坛能够修改他人帖子
中危:LOFTER网页版发帖存在存储型XSS漏洞
中危:LOFTER网页端依然存在数个敏感信息泄露
中危: LOFTER网页端存在敏感信息泄露
低危: 网易云音乐投资存在反射型XSS
subscribe via RSS