当前位置:网站首页>Vulfocus entry target
Vulfocus entry target
2022-06-30 07:53:00 【sec0nd_】
List of articles
Command Execution Vulnerability
Vulnerability description :
Command execution (Command Execution) Vulnerability means that hackers can directly Web Execute system commands in the application , To get sensitive information or win shell jurisdiction
The possible causes of command execution vulnerability are Web Insufficient security detection of user input commands by the server , Cause malicious code to be executed
Open the vulnerability address , Directly write out the parameters of the command execution 
Visit the address , return flag

Directory traversal vulnerability
Vulnerability description :
Directory browsing vulnerability is a kind of directory traversal vulnerability , The directory browsing vulnerability is due to a configuration defect in the website , There is a directory browsable vulnerability , This will lead to the disclosure of many private files and directories on the website , For example, database backup files 、 Configuration files, etc , Using this information, an attacker can get the website permission more easily , Cause the website to be hacked .
risk : When an attacker accesses a directory of a website , The directory does not have a default home page file or the default home page file is not set correctly , The entire directory structure will be listed , Completely expose the website structure to the attacker ;
The attacker may browse the directory structure , Access to some secret files ( Such as PHPINFO file 、 Server probe file 、 Website administrator background access address 、 Database connection files, etc ).
Open the vulnerability address , Is similar to ftp Pages of the site 
Came to tmp Under the table of contents , There is one flag( I thought it might be a fake flag, The submission was successful , A little insulting to IQ )
边栏推荐
- ACM. Hj48 delete the node with the specified value from the one-way linked list ●●
- Directory of software
- National technology n32g45x series about timer timing cycle calculation
- Disk space, logical volume
- 期末複習-PHP學習筆記3-PHP流程控制語句
- 深度学习——序列模型and数学符号
- Examen final - notes d'apprentissage PHP 5 - Tableau PHP
- Projection point of point on line
- C language operators
- 为什么大学毕业了还不知道干什么?
猜你喜欢

深度学习——网络中的网络以及1x1卷积

期末复习-PHP学习笔记8-mysql数据库

At the end of June, you can start to make preparations, otherwise you won't have a share in such a profitable industry
![November 9, 2020 [wgs/gwas] - whole genome analysis (association analysis) process (Part 2)](/img/21/ad74700921ee0ef7a1525dd7db0683.jpg)
November 9, 2020 [wgs/gwas] - whole genome analysis (association analysis) process (Part 2)

Efga design open source framework openlane series (I) development environment construction

【花雕体验】14 行空板pinpong库测试外接传感器模块(之一)

Cross compile opencv3.4 download cross compile tool chain and compile (3)

CRM&PM如何帮助企业创造最优销售绩效

Account command and account authority

mysql无法连接内网的数据库
随机推荐
More, faster, better and cheaper. Here comes the fastdeploy beta of the low threshold AI deployment tool!
Personal blog one article multi post tutorial - basic usage of openwriter management tool
Xiashuo think tank: 125 planet updates reported today (packed with 101 meta universe collections)
At the end of June, you can start to make preparations, otherwise you won't have a share in such a profitable industry
Intersection of two lines
2021 private equity fund market report (62 pages)
Final review -php learning notes 4-php custom functions
Efga design open source framework openlane series (I) development environment construction
2022.01.20 [bug note] | qiime2: an error was encoded while running dada2 in R (return code 1)
期末复习-PHP学习笔记5-PHP数组
深度学习——网络中的网络以及1x1卷积
C. Fishingprince Plays With Array
right four steps of SEIF SLAM
Halcon12+vs2013 C # configuration
Deep learning -- feature point detection and target detection
直击产业落地 | 飞桨重磅推出业界首个模型选型工具
Use of nested loops and output instances
December 4, 2021 [metagenome] - sorting out the progress of metagenome process construction
Common sorting methods
December 13, 2021 [reading notes] | understanding of chain specific database building