#漏洞 PHP Composer命令注入漏洞(CVE-2021-29472)
https://blog.sonarsource.com/php-supply-chain-attack-on-composer
https://blog.sonarsource.com/php-supply-chain-attack-on-composer
Sonarsource
PHP Supply Chain Attack on Composer
We recently discovered a vulnerability in Composer, the main package manager for PHP, and were able to use it to take over the central repository, packagist.org.
#漏洞 TG8 防火墙中的 RCE 和密码泄漏
https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/
https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/
SSD Secure Disclosure
SSD Advisory – TG8 Firewall PreAuth RCE and Password Disclosure - SSD Secure Disclosure
TL;DR Find out how vulnerabilities in TG8 Firewall allows remote unauthenticated users to execute arbitrary code on the remote device as well as disclose the passwords of existing accounts. Vulnerability Summary Two security vulnerabilities in TG8 Firewall…
#漏洞 CVE-2021-32030:ASUS GT-AC2900身份验证绕过
https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass
https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass
Atredis Partners
CVE-2021-32030: ASUS GT-AC2900 Authentication Bypass — Atredis Partners
In a previous blog post I had presented a creative method to resurrect a bricked device, in this post I will go over an authentication bypass vulnerability discovered within the running firmware.
#漏洞 Another Windows Installer Local Privilege Escalation Bug Gets a Micropatch (CVE-2021-26415)
https://blog.0patch.com/2021/05/another-windows-installer-local.html
https://blog.0patch.com/2021/05/another-windows-installer-local.html
0Patch
Another Windows Installer Local Privilege Escalation Bug Gets a Micropatch (CVE-2021-26415)
by Mitja Kolsek, the 0patch Team On April 21, security researcher Adrian Denkiewicz published an in-depth analysis of a local privilege...
#漏洞 Ivanti Avalanche 目录遍历漏洞
https://ssd-disclosure.com/ssd-advisory-ivanti-avalanche-directory-traversal/
https://ssd-disclosure.com/ssd-advisory-ivanti-avalanche-directory-traversal/
SSD Secure Disclosure
SSD Advisory – Ivanti Avalanche Directory Traversal - SSD Secure Disclosure
Find out how a directory traversal vulnerability in Ivanti Avalanche allows remote unauthenticated user to access files that reside outside the 'image' folder.
#漏洞 【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
Weixin Official Accounts Platform
【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
CVE-2021-29200 Apache OFBiz RMI Bypass RCE ,通过黑名单绕过,从而造成一个反序列化远程命令执行漏洞
#漏洞 Open Distro for Elasticsearch SSRF漏洞(CVE-2021-31828)
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
My Publications
CVE-2021-31828 - SSRF in Open Distro for ElasticSearch
#漏洞 CVE‑2021‑1079 – NVIDIA GeForce Experience命令执行
https://voidsec.com/nvidia-geforce-experience-command-execution/
https://voidsec.com/nvidia-geforce-experience-command-execution/
VoidSec
CVE‑2021‑1079 - NVIDIA GeForce Experience Command Execution - VoidSec
CVE-2021-1079: NVIDIA GeForce Experience (GFE) v.<= 3.21 is affected by an Arbitrary File Write vulnerability which lead to Command Execution.
#漏洞 Cisco RV34X系列 权限提升漏洞(CVE-2021-1520)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
ONEKEY
Advisory: Cisco RV34X Series - Privilege Escalation in vpnTimer - ONEKEY
IoT Inspector detected a rare security vulnerability in Cisco's RV34X Series. Read the full root analysis on the blog!