CVE-2025-66945 (An authenticated Directory Traversal in Zdir Pro 4.x)

Product Overview Zdir Pro is a multifunctional private file sharing and storage program that provides web-based file indexing, preview, management, and sharing capabilities. It is designed to serve as a self-hosted file portal, supporting features such as online preview of images, audio, video and documents, global file search, WebDAV access, and offline/cloud downloads. The software allows users to mount network storage like S3 and WebDAV for unified management and supports operations including upload, download, move, rename, delete, and API integration. ...

March 2, 2026 · 5 min · 959 words · endlessparadox

CVE-2025-66944 (An authenticated SQL injection in databasir)

Product Overview Databasir is an open-source, web-based database management and data visualization platform designed to simplify database exploration and collaboration. The project is hosted on GitHub and provides a modern interface for managing relational databases. Databasir supports multiple database systems and offers features such as schema visualization, table browsing, SQL query execution, data editing, and permission management. It is designed to help teams understand database structures, document schemas, and perform data operations through a centralized web interface. The platform is commonly deployed in internal environments to improve database transparency and operational efficiency. ...

March 1, 2026 · 2 min · 296 words · endlessparadox

CVE-2025-70525 (Arbitrary IP address spoofing vulnerability In go-drive)

Product Overview go-drive is an open-source web-based file management application written in Go and hosted on GitHub. The project provides a lightweight web interface that allows users to manage and access multiple storage backends through a unified system. It supports various storage drivers, including local file systems, FTP/SFTP, WebDAV, S3-compatible object storage, OneDrive, and Google Drive. The application offers features such as file upload and download, drag-and-drop support, directory management, image preview, text/code editing, permission control, and WebDAV access. The project is distributed under the MIT License. ...

March 1, 2026 · 2 min · 294 words · endlessparadox

Hello World!

Start Hack the world

September 6, 2025 · 1 min · 4 words · endlessparadox