#漏洞 北京致远G6政务协同系统V6.1SP1 反射性xss漏洞 CVE-2020-20545
https://note.youdao.com/ynoteshare1/index.html?id=29f908204968a79233c1c0c80a59f8ff&type=note
https://note.youdao.com/ynoteshare1/index.html?id=29f908204968a79233c1c0c80a59f8ff&type=note
#漏洞 VMware vRealize Operations Manager API SSRF漏洞 (CVE-2021-21975)
https://github.com/projectdiscovery/nuclei-templates/blob/master/cves/2021/CVE-2021-21975.yaml
https://github.com/projectdiscovery/nuclei-templates/blob/master/cves/2021/CVE-2021-21975.yaml
GitHub
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities. - projectdiscovery/nuclei-templates
#漏洞 POC for CVE-2021-24098, a Denial Of Service bug in condrv.sys.
https://github.com/waleedassar/CVE-2021-24098
https://github.com/waleedassar/CVE-2021-24098
GitHub
GitHub - waleedassar/CVE-2021-24098: POC for CVE-2021-24098
POC for CVE-2021-24098. Contribute to waleedassar/CVE-2021-24098 development by creating an account on GitHub.
#漏洞 mongo-express中的远程代码执行-CVE-2020-24391
https://securitylab.github.com/advisories/GHSL-2020-131-mongo-express/
https://securitylab.github.com/advisories/GHSL-2020-131-mongo-express/
GitHub Security Lab
GHSL-2020-131: Remote Code Execution in mongo-express - CVE-2020-24391
Mongo-express uses safer-eval to validate user supplied javascript. Unfortunately safer-eval sandboxing capabilities are easily bypassed leading to RCE in the context of the node server.
#漏洞 Zero click vulnerability in Apple’s macOS Mail
https://mikko-kenttala.medium.com/zero-click-vulnerability-in-apples-macos-mail-59e0c14b106c
https://mikko-kenttala.medium.com/zero-click-vulnerability-in-apples-macos-mail-59e0c14b106c
Medium
Zero click vulnerability in Apple’s macOS Mail
Zero-Click Zip TL;DR
#bountytip I Built a TV That Plays All of Your Private YouTube Videos
https://bugs.xdavidhu.me/google/2021/04/05/i-built-a-tv-that-plays-all-of-your-private-youtube-videos/
https://bugs.xdavidhu.me/google/2021/04/05/i-built-a-tv-that-plays-all-of-your-private-youtube-videos/
bugs.xdavidhu.me
I Built a TV That Plays All of Your Private YouTube Videos
David Schütz's bug bounty writeups
#漏洞 WordPress插件Tutor LMS SQL注入漏洞(CVE-2021-24186)
https://wpscan.com/vulnerability/5f5c0c6c-6f76-4366-b590-0aab557f8c60
https://wpscan.com/vulnerability/5f5c0c6c-6f76-4366-b590-0aab557f8c60
#漏洞 WordPress WP Super Cache 插件 < 1.7.2 RCE(CVE-2021-24209)
https://wpscan.com/vulnerability/733d8a02-0d44-4b78-bbb2-37e447acd2f3
https://wpscan.com/vulnerability/733d8a02-0d44-4b78-bbb2-37e447acd2f3
WPScan
WP Super Cache < 1.7.2 - Authenticated Remote Code Execution (RCE)
See details on WP Super Cache < 1.7.2 - Authenticated Remote Code Execution (RCE) CVE 2021-24209. View the latest Plugin Vulnerabilities on WPScan.
#漏洞 WordPress Elementor Page Builder Plus插件身份验证绕过(CVE-2021-24175)
https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89
https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89