#漏洞 BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
https://google.github.io/security-research/pocs/linux/bleedingtooth/
https://google.github.io/security-research/pocs/linux/bleedingtooth/
security-research
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
#漏洞 Nagios Network Analyzer SQL 注入漏洞(CVE-2021-28925)
https://medium.com/stolabs/issues-found-on-nagios-network-analyzer-2-4-2-50ec4ffb5e25
https://medium.com/stolabs/issues-found-on-nagios-network-analyzer-2-4-2-50ec4ffb5e25
Medium
Issues Found on Nagios Network Analyzer 2.4.2
During the time of 2020, I was preparing for a certification called OSWE. The path has been long and with curves, because sometimes we…
#漏洞 Four Bytes of Power: exploiting CVE-2021-26708 in the Linux kernel
https://a13xp0p0v.github.io/2021/02/09/CVE-2021-26708.html
https://a13xp0p0v.github.io/2021/02/09/CVE-2021-26708.html
Alexander Popov
Four Bytes of Power: Exploiting CVE-2021-26708 in the Linux kernel
CVE-2021-26708 is assigned to five race condition bugs in the virtual socket implementation of the Linux kernel. I discovered and fixed them in January 2021. In this article I describe how to exploit them for local privilege escalation on Fedora 33 Server…
#漏洞 D-LINK DIR-802 命令注入漏洞(CVE-2021-29379)
https://cool-y.github.io/2021/03/02/DIR-802-OS-Command-Injection/
https://cool-y.github.io/2021/03/02/DIR-802-OS-Command-Injection/
混元霹雳手
DIR-802 OS Command Injection
提交个漏洞
#漏洞 Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316)
https://shenaniganslabs.io/2021/04/13/Airstrike.html
https://shenaniganslabs.io/2021/04/13/Airstrike.html
Shenanigans Labs
Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316)
By default, domain joined Windows workstations allow access to the network selection UI from the lock screen.
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
#漏洞 Cisco RV34X系列–身份验证绕过和远程命令执行(CVE-2021-1472/CVE-2021-1473)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
#漏洞 Allow arbitrary URLs, expect arbitrary code execution
https://positive.security/blog/url-open-rce
https://positive.security/blog/url-open-rce
positive.security
Allow arbitrary URLs, expect arbitrary code execution | Positive Security
Insecure URL handling leading to 1-click code execution vulnerabilities in Telegram, Nextcloud (CVE-2021-22879), VLC, LibreOffice (CVE-2021-25631), OpenOffice (CVE-2021-30245), Bitcoin/Dogecoin Wallets, Wireshark (CVE-2021-22191) and Mumble (CVE-2021-27229).
#漏洞 WordPress 5.6-5.7 - Authenticated XXE (CVE-2021-29447)
https://github.com/motikan2010/CVE-2021-29447
https://github.com/motikan2010/CVE-2021-29447
GitHub
GitHub - motikan2010/CVE-2021-29447: WordPress - Authenticated XXE (CVE-2021-29447)
WordPress - Authenticated XXE (CVE-2021-29447). Contribute to motikan2010/CVE-2021-29447 development by creating an account on GitHub.