首页 > 专栏 > PHP Bugs PHP Bugs 共 250 条资讯 WordPress: Author → arbitrary file deletion anywhere on disk (site takeover) via `POST /wp/v2/media/<id>/finalize` poisoning `_wp_attachment_metadata` 2026-06-27 16:20:01 IBM: Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint 2026-06-27 16:20:01 curl: 42: `VMS_STS` macro typo (`< 3` vs `<< 3`) turns curl failures into successful OpenVMS conditions 2026-06-27 16:20:01 curl: 50: CMake `HTTP_ONLY` does not disable SSH backends — SCP and SFTP remain usable 2026-06-27 16:20:01 Essity: Critical SQL Injection WDM API (████████) 2026-06-27 16:20:01 Essity: Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit) 2026-06-27 16:20:01 curl: ARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds 2026-06-27 16:20:01 curl: Unbound cross-peer HTTP Digest challenge state 2026-06-27 16:20:01 GitHub: Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating 2026-06-27 16:20:01 Discourse: Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization 2026-06-27 16:20:01 curl: curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack 2026-06-27 16:20:01 Ruby on Rails: URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag 2026-06-27 16:20:01 curl: wolfSSL backend disables hostname verification when CURLOPT_SSL_VERIFYPEER is 0 2026-06-27 16:20:01 curl: RTSP CRLF injection in libcurl allows CURLOPT_RTSP_* values to inject commands into independent sessions 2026-06-27 16:20:01 8x8: @jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration) 2026-06-27 16:20:01 curl: libcurl Digest/NTLM authentication ignores an explicit Authorization header 2026-06-27 16:20:01 curl: TLS session cache case-folds CA paths and bypasses the active trust profile 2026-06-27 16:20:01 Nextcloud: Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider 2026-06-27 16:20:01 Rocket.Chat: Stored HTML Injection (CWE-79) via Livechat Visitor Name 2026-06-27 16:20:01 Rocket.Chat: DDP methods getThreadsList / getThreadMessages leaks private thread content to any authenticated low privilege user (unpatched sibling of #1446767) 2026-06-27 16:20:01 « 上一页1…56789…13下一页 » 相关分类 P #!/slash/note #UNTAG (B)(F)uzzing on my world (Hi)story (IN)SECURE Magazine Notification (gdb) break *0x972 - 带鱼博客 BeltfishBlog - ./kwaa.dev .NET Blog .Trash /home/rook1e 00's Adventure 0kami's Blog 0x41414141 in ?? () 0x7f Blog 0xRick Owned Root ! 0xd00's blog 1 Byte 1A23 Blog 1A23 Studio 1Link.Fun 1stwebdesigner 251 2BAB 的工程博客 2ch中文网 360 CERT 360 Netlab Blog - Network Securi 38号车评中心 3o米的微博