[标题搜索]只能搜索题目标题,[综合搜索]支持多关键词多项目搜索(以空格分隔)。
| 序号 | Website | Type | Title | Value | Writeup | Competition | Id |
|---|---|---|---|---|---|---|---|
| 1 | ctfshow | 网络迷踪.七夕杯 | 社工签到 | ctfshow{天涯小镇} | https://cn-sec.com/archives/2306326.html | 七夕杯 | 4675 |
| 2 | ctfshow | WEB入门.中期测评 | web487 | sqlmap -u "https://648b315b-136d-427f-b332-417f4865f221.challenge.ctf.show/index.php?action=check&username=1&password=1" --batch -T ctf -C ctf --dumps | ... | 中期测评 | 3893 |
| 3 | ctfshow | WEB.2023愚人杯 | easy_php | ctfshow{7180858b-b87e-450d-8944-a3d719f92ada} | https://blog.csdn.net/weixin_63231007... | 2023愚人杯 | 4821 |
| 4 | cyberstrikelab | 新手必玩 | 仿真靶标pikachu | 无 | https://blog.csdn.net/m0_72235421/art... | cyberstrikelab | 16943 |
| 5 | bugku | WEB | Curl as a Service | n00bz{4rb1t4ry_f1le_re4d_us1ng_curl_ftw!} | https://ctf.bugku.com/writeup/detail/... | n00bzCTF2022 | 2214 |
| 6 | vulfocus | WEB | wordpress远程代码执行(CVE-2019-8942) | 无 | 验证后的网址 WordPress 5.0.0 的远程代码执行漏洞(CVE-... | - | 16503 |
| 7 | BUUCTF | Web | [HarekazeCTF2019]Avatar Uploader 1 | 题目的答案 | https://blog.csdn.net/weixin_44037296... | HarekazeCTF2019 | 6823 |
| 8 | bugku | WEB | Upload 2 | shellmates{4_No7_O_EcuRE_d0Cker_iMAG3_f0r_4p4ch3} | https://blog.csdn.net/m0_74625079/art... | HackINI2023 | 339 |
| 9 | 封神台 | CRYPTO | 解密题(考点:base91解码) | - | https://bbs.zkaq.cn/t/6246.html#CTF-95 | - | 14988 |
| 10 | vulfocus | WEB | nagiosxi SQL注入 (CVE-2018-10737) | NagiosXI <= 5.4.12 存在 SQL 注入漏洞(CVE-2018-10737),攻击者可通过 admin/logbook.php 的 txtSearch 参数执行任意 SQL 命令。受影响版本为 5.2.x 和 5.4.x(<5.4.13),修复方法为升级至 5.4.13 或以上版本。漏洞 PoC 示例为: POST /nagiosql/admin/logbook.php txtSearch=-1%' and (select 1 from(select count(*),concat((select (select (select concat(0x7e,version(),0x7e))) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)# 验证后的网址为:https://www.seebug.org/vuldb/ssvid-97267 | https://www.seebug.org/vuldb/ssvid-97267 | - | 16622 |