The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before ...
本内容遵循CC 4.0 BY-SA版权协议 很多朋友在入门网络安全时,面对海量的工具和概念常常感到无从下手,尤其是在搭建环境、理解攻击原理和进行实战演练这几个关键环节。网上的资料要么过于 ...
A single unauthenticated HTTP request to Metabase's password-reset endpoint was all it took for an attacker to gain full administrator access to an analytics platform trusted by tens of thousands of ...
Storage code has to cope with hardware that fails in inconvenient ways, but coaxing a healthy disk into producing those failures on demand, for testing, is usually not possible. The kernel provides ...
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside the database and gain SYSTEM-level access to the underlying Windows server.
原创 最新推荐文章于 2026-07-02 09:12:54 发布 · 333 阅读 如果你刚接触网络安全,或者对Kali Linux和Web渗透测试充满好奇,那么“SQL注入与XSS漏洞攻防”这个主题,几乎就是为你量身定制的入门实战手册 ...
Offensive Security has announced the release of Kali Linux 2026.2, the second update for this year of their security-focused Linux distribution. The new version introduces nine additional tools, ...
Offensive Security shipped Kali Linux 2026.2 on Monday, June 29, delivering the most technically disciplined point release the project has produced in recent memory. The update hands penetration ...
The Kali Linux team has officially released Kali Linux 2026.2, arriving right on schedule at the close of Q2 2026. This release delivers a powerful combination of desktop environment upgrades, VM ...
Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. The Kali Linux distro is designed for cybersecurity ...
A critical SQL injection vulnerability in ProFTPD’s mod_sql extension, tracked as CVE-2026-42167, that enables remote code execution, authentication bypass, and privilege escalation in some ...