#漏洞 mongo-express中的远程代码执行-CVE-2020-24391
https://securitylab.github.com/advisories/GHSL-2020-131-mongo-express/
https://securitylab.github.com/advisories/GHSL-2020-131-mongo-express/
GitHub Security Lab
GHSL-2020-131: Remote Code Execution in mongo-express - CVE-2020-24391
Mongo-express uses safer-eval to validate user supplied javascript. Unfortunately safer-eval sandboxing capabilities are easily bypassed leading to RCE in the context of the node server.
#漏洞 Zero click vulnerability in Apple’s macOS Mail
https://mikko-kenttala.medium.com/zero-click-vulnerability-in-apples-macos-mail-59e0c14b106c
https://mikko-kenttala.medium.com/zero-click-vulnerability-in-apples-macos-mail-59e0c14b106c
Medium
Zero click vulnerability in Apple’s macOS Mail
Zero-Click Zip TL;DR
#bountytip I Built a TV That Plays All of Your Private YouTube Videos
https://bugs.xdavidhu.me/google/2021/04/05/i-built-a-tv-that-plays-all-of-your-private-youtube-videos/
https://bugs.xdavidhu.me/google/2021/04/05/i-built-a-tv-that-plays-all-of-your-private-youtube-videos/
bugs.xdavidhu.me
I Built a TV That Plays All of Your Private YouTube Videos
David Schütz's bug bounty writeups
#漏洞 WordPress插件Tutor LMS SQL注入漏洞(CVE-2021-24186)
https://wpscan.com/vulnerability/5f5c0c6c-6f76-4366-b590-0aab557f8c60
https://wpscan.com/vulnerability/5f5c0c6c-6f76-4366-b590-0aab557f8c60
#漏洞 WordPress WP Super Cache 插件 < 1.7.2 RCE(CVE-2021-24209)
https://wpscan.com/vulnerability/733d8a02-0d44-4b78-bbb2-37e447acd2f3
https://wpscan.com/vulnerability/733d8a02-0d44-4b78-bbb2-37e447acd2f3
WPScan
WP Super Cache < 1.7.2 - Authenticated Remote Code Execution (RCE)
See details on WP Super Cache < 1.7.2 - Authenticated Remote Code Execution (RCE) CVE 2021-24209. View the latest Plugin Vulnerabilities on WPScan.
#漏洞 WordPress Elementor Page Builder Plus插件身份验证绕过(CVE-2021-24175)
https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89
https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89
#漏洞 Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys.
https://github.com/0vercl0k/CVE-2021-24086
https://github.com/0vercl0k/CVE-2021-24086
GitHub
GitHub - 0vercl0k/CVE-2021-24086: Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.
Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely. - 0vercl0k/CVE-2021-24086
#漏洞 BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
https://google.github.io/security-research/pocs/linux/bleedingtooth/
https://google.github.io/security-research/pocs/linux/bleedingtooth/
security-research
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
#漏洞 Nagios Network Analyzer SQL 注入漏洞(CVE-2021-28925)
https://medium.com/stolabs/issues-found-on-nagios-network-analyzer-2-4-2-50ec4ffb5e25
https://medium.com/stolabs/issues-found-on-nagios-network-analyzer-2-4-2-50ec4ffb5e25
Medium
Issues Found on Nagios Network Analyzer 2.4.2
During the time of 2020, I was preparing for a certification called OSWE. The path has been long and with curves, because sometimes we…