Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-24132: GitHub - zpxlz/phpshe: phpshe

phpshe V1.8 is affected by a denial of service (DoS) attack in the registry’s verification code, which can paralyze the target service.

CVE
#vulnerability#web#dos#git

Program download address. http://www.phpshe.com/down/phpshe1.8.rar

Of course, there are packages in this project.(phpshe1.8.rar)

There is a denial of access vulnerability in the registry’s verification code. image

I deployed the website with my own server, Click the verification code to refresh the verification code, and then grab the request package, Modify the length and width parameters of the verification code image, and you can see that the returned data is very long, image

I didn’t set up many threads, just 50, and my server (4-core 8G) almost crashed. image

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907