Posts
-
Gitlab Html Injection in file search
-
2024 Intigriti CTF, some Web solution
-
CVE-2024-39903: Local File Inclusion in Solara
-
Arbitrary File Overwrite in jupyter notebook
-
Zipslip when parsing invoice zip file via InvoiceOCRAssistant in metagpt
-
XSS in Siyuan Electron App when rendering mermaid block diagram Leading to RCE(Just Thanks)
-
XSS in Bluestone Electron App when rendering mermaid class diagram Leading to RCE(Just Thanks)
-
XSS in Outline when rendering mermaid diagrams(No Security Impact!)
-
Arbitrary File Overwrite via unstructured-ingest in unstructured(Just Thanks)
-
Remote Code Execution via Arbitrary File Overwrite Using Path Traversal in intel-extension-for-transformers neural_chat
-
Arbitrary File Deletion via Path Traversal in intel-extension-for-transformers neural_chat
-
Remote Code Execution via Arbitrary File Overwrite Using Path Traversal in langflow Pre-release(No Response)
-
Google: Local File Inclusion in FHIR Pipelines Controller
-
Hackerone: Store XSS in Gitness markdown comment editor
-
Google: Local File Inclusion in Turbinia API Server
-
Dev.to(Forem) cta xss(No Response,But Fixed!)
-
CVE-2024-32005: Local File Inclusion in NiceGUI leaflet component
-
Remote Code Execution via Arbitrary File Overwrite Using Path Traversal in agent-protocol
-
高危:有道智云存在微博OAuth2登录缺陷串联XSS漏洞实现账户劫持(忽略!)
-
CVE-2024-5187: Arbitrary File Overwrite in onnx
-
中危:网易灵犀企业邮箱存在存储型XSS漏洞
-
高危:网易云课堂ai设计工坊存在文件读取漏洞
-
中危:有道云笔记网页版思维导图存在存储型XSS漏洞
-
中危:有道云笔记网页版白板存在存储型XSS漏洞
-
中危:有道云笔记网页端渲染流程图存在存储型XSS漏洞
-
中危:有道云笔记markdown模式渲染类图(classDiagram)存储型XSS漏洞
-
Reproduction: Gitlab Arbitrary file read via the bulk imports UploadsPipeline
-
Reproduction: Gitlab Arbitrary file read via the UploadsRewriter when moving and issue
-
Gitlab debugging: Using gitlab official docker to debug rails backend
-
Reproduction: Gitlab Cross-site Scripting (XSS) - Stored in RDoc wiki pages
-
Reproduction: Gitlab Stored XSS in markdown when redacting references
-
Reproduction: Gitlab Stored XSS via Kroki diagram
-
Reproduction: Gitlab Stored-XSS with CSP-bypass via labels' color
-
Reproduction: Gitlab CSP-bypass XSS in project settings page
-
高危:网易大神手机客户端Webview mxss漏洞
-
中危:网易大神Web端频道签到消息存储型XSS漏洞
-
中危:网易大神Web端频道分享帖子存储型XSS漏洞
-
低危:网易UU论坛深井Web版评论等功能存在SSRF漏洞
-
中危(重复):网易UU论坛深井Web发帖和回复存储型XSS漏洞
-
中危:网易天工网站wordpress主题discy未授权访问
-
中危:网易数帆-codewave开发论坛未授权修改用户信息
-
中危:网易数帆-codewave开发论坛敏感信息泄露
-
高危:网易数帆codewave开发论坛能够修改他人帖子
-
中危:LOFTER网页版发帖存在存储型XSS漏洞
-
中危:LOFTER网页端依然存在数个敏感信息泄露
-
中危: LOFTER网页端存在敏感信息泄露
-
低危: 网易云音乐投资存在反射型XSS
subscribe via RSS