#漏洞 CVE-2021-23888-McAfee ePolicy Orchestrator HTML注入
https://ricardojba.github.io/CVE-2021-23888-McAfee-ePolicy-Orchestrator-HTML-Injection/
https://ricardojba.github.io/CVE-2021-23888-McAfee-ePolicy-Orchestrator-HTML-Injection/
blog.vibri.us
CVE-2021-23888 McAfee ePolicy Orchestrator HTML Injection | vibrio's personal infosec blog
Product: McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 Type: OWASP Top Ten 2013 Category A10 - Unvalidated Redirects and Forwards Summary: Unvali...
#bountytip How to bypass CloudFlare bot protection ?
https://jychp.medium.com/how-to-bypass-cloudflare-bot-protection-1f2c6c0c36fb
https://jychp.medium.com/how-to-bypass-cloudflare-bot-protection-1f2c6c0c36fb
Medium
How to bypass CloudFlare bot protection ?
Several months ago I submitted what appeared to be a security flaw to CloudFalre’s bugbounty program. According to them, this is not a…
#漏洞 Afterlogic Aurora & WebMail Pro 文件上传漏洞(CVE-2021-26293)
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26293-rce-via-public-unrestricted-file-upload-vulnerability.md
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26293-rce-via-public-unrestricted-file-upload-vulnerability.md
GitHub
AfterLogic/CVE-2021-26293-rce-via-public-unrestricted-file-upload-vulnerability.md at main · E3SEC/AfterLogic
AfterLogic Products Vulnerabilities. Contribute to E3SEC/AfterLogic development by creating an account on GitHub.
#漏洞 Afterlogic Aurora & WebMail Pro 任意文件读取(CVE-2021-26294)
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26294-exposure-of-sensitive-information-vulnerability.md
https://github.com/E3SEC/AfterLogic/blob/main/CVE-2021-26294-exposure-of-sensitive-information-vulnerability.md
GitHub
AfterLogic/CVE-2021-26294-exposure-of-sensitive-information-vulnerability.md at main · E3SEC/AfterLogic
AfterLogic Products Vulnerabilities. Contribute to E3SEC/AfterLogic development by creating an account on GitHub.
#漏洞 Universal “netmask” npm package, used by 270,000+ projects, vulnerable to octal input data: server-side request forgery, remote file inclusion, local file inclusion, and more (CVE-2021-28918)
https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/
https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/
Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
Universal "netmask" npm package, used by 270,000+ projects, vulnerable to octal input data: server-side request forgery, remote…
The following research outlines a vulnerability discovered in netmask npm package that is currently used by 278,722+ other projects. The vulnerability has been present for 9 years. Since this package is so incredibly widespread, I would suggest every nodejs…
#情报 PHP的Git服务器被黑客入侵以向PHP源代码添加后门
https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/
https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/
BleepingComputer
PHP's Git server hacked to add backdoors to PHP source code
In the latest software supply chain attack, the official PHP Git repository was hacked and tampered with. Yesterday, two malicious commits were pushed to the php-src Git repository maintained by the PHP team on their git.php.net server. The threat actors…
#漏洞 Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
https://blog.0patch.com/2021/03/analyzing-and-micropatching-with.html
https://blog.0patch.com/2021/03/analyzing-and-micropatching-with.html
0Patch
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
by Mitja Kolsek, the 0patch Team March 2021 Windows Updates included fixes for seven vulnerabilities in Windows DNS Server, two of which w...
#漏洞 POC for CVE-2021-1656, an information disclosure in tpm.sys.
https://github.com/waleedassar/CVE-2021-1656
https://github.com/waleedassar/CVE-2021-1656
GitHub
GitHub - waleedassar/CVE-2021-1656
Contribute to waleedassar/CVE-2021-1656 development by creating an account on GitHub.
#漏洞 DD-WRT 缓冲区溢出漏洞(CVE-2021-27137)
https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
SSD Secure Disclosure
SSD Advisory – DD-WRT UPNP Buffer Overflow - SSD Secure Disclosure
TL;DR Find out how a vulnerability in DD-WRT allows an unauthenticated attacker to overflow an internal buffer used by UPNP and trigger a code execution vulnerability. Vulnerability Summary DD-WRT is “is Linux-based firmware for wireless routers and access…