首页 > 专栏 > PHP Bugs PHP Bugs 共 103 条资讯 AWS VDP: Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh 2026-06-27 16:20:01 Monero: ZMQ RPC Log Injection and Untrusted Payload Persistence 2026-06-27 16:20:01 [$1337] 8x8: connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability 2026-06-27 16:20:01 GitHub: GitHub user to server tokens can create issues in any public repository 2026-06-27 16:20:01 AWS VDP: AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF 2026-06-27 16:20:01 GitHub: OAuth redirect uri validation bypass for :proxima_first_party_sync apps 2026-06-27 16:20:01 Monero: Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes 2026-06-27 16:20:01 AWS VDP: Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections 2026-06-27 16:20:01 GitHub: Able to bypass authorization logic and gain more access then intended 2026-06-27 16:20:01 Rocket.Chat: Stored XSS in Rocket.Chat HTML File Export — Unauthenticated Entry via LiveChat 2026-06-27 16:20:01 AWS VDP: bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys 2026-06-27 16:20:01 [$337] Basecamp: Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass 2026-06-27 16:20:01 SingleStore: SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server 2026-06-27 16:20:01 AWS VDP: Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644) 2026-06-27 16:20:01 AWS VDP: OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE) 2026-06-27 16:20:01 [$287] Basecamp: Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity 2026-06-27 16:20:01 Yelp: Yelp for Business: locked Email field silently editable via API 2026-06-27 16:20:01 [$100] 8x8: jitsi-call-analytics: Unauthenticated arbitrary file write via path traversal in `/api/v1/uploads/analyze` 2026-06-27 16:20:01 [$100] 8x8: jitsi-meet: Prosody/Jigasi missing header whitelist in mod_filter_iq_rayo allows arbitrary SIP header injection and Caller ID spoofing 2026-06-27 16:20:01 AWS VDP: Non-Production API Endpoints for the Amazon S3 Tables Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration 2026-06-27 16:20:01 « 上一页123456下一页 » 相关分类 P #!/slash/note #UNTAG (B)(F)uzzing on my world (Hi)story (IN)SECURE Magazine Notification (gdb) break *0x972 - 带鱼博客 BeltfishBlog - ./kwaa.dev .NET Blog .Trash /home/rook1e 00's Adventure 0kami's Blog 0x41414141 in ?? () 0x7f Blog 0xRick Owned Root ! 0xd00's blog 1 Byte 1A23 Blog 1A23 Studio 1Link.Fun 1stwebdesigner 251 2BAB 的工程博客 2ch中文网 360 CERT 360 Netlab Blog - Network Securi 38号车评中心 3o米的微博