#漏洞 CVE-2021-32030:ASUS GT-AC2900身份验证绕过
https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass
https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass
Atredis Partners
CVE-2021-32030: ASUS GT-AC2900 Authentication Bypass — Atredis Partners
In a previous blog post I had presented a creative method to resurrect a bricked device, in this post I will go over an authentication bypass vulnerability discovered within the running firmware.
#漏洞 Another Windows Installer Local Privilege Escalation Bug Gets a Micropatch (CVE-2021-26415)
https://blog.0patch.com/2021/05/another-windows-installer-local.html
https://blog.0patch.com/2021/05/another-windows-installer-local.html
0Patch
Another Windows Installer Local Privilege Escalation Bug Gets a Micropatch (CVE-2021-26415)
by Mitja Kolsek, the 0patch Team On April 21, security researcher Adrian Denkiewicz published an in-depth analysis of a local privilege...
#漏洞 Ivanti Avalanche 目录遍历漏洞
https://ssd-disclosure.com/ssd-advisory-ivanti-avalanche-directory-traversal/
https://ssd-disclosure.com/ssd-advisory-ivanti-avalanche-directory-traversal/
SSD Secure Disclosure
SSD Advisory – Ivanti Avalanche Directory Traversal - SSD Secure Disclosure
Find out how a directory traversal vulnerability in Ivanti Avalanche allows remote unauthenticated user to access files that reside outside the 'image' folder.
#漏洞 【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
Weixin Official Accounts Platform
【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
CVE-2021-29200 Apache OFBiz RMI Bypass RCE ,通过黑名单绕过,从而造成一个反序列化远程命令执行漏洞
#漏洞 Open Distro for Elasticsearch SSRF漏洞(CVE-2021-31828)
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
My Publications
CVE-2021-31828 - SSRF in Open Distro for ElasticSearch
#漏洞 CVE‑2021‑1079 – NVIDIA GeForce Experience命令执行
https://voidsec.com/nvidia-geforce-experience-command-execution/
https://voidsec.com/nvidia-geforce-experience-command-execution/
VoidSec
CVE‑2021‑1079 - NVIDIA GeForce Experience Command Execution - VoidSec
CVE-2021-1079: NVIDIA GeForce Experience (GFE) v.<= 3.21 is affected by an Arbitrary File Write vulnerability which lead to Command Execution.
#漏洞 Cisco RV34X系列 权限提升漏洞(CVE-2021-1520)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
ONEKEY
Advisory: Cisco RV34X Series - Privilege Escalation in vpnTimer - ONEKEY
IoT Inspector detected a rare security vulnerability in Cisco's RV34X Series. Read the full root analysis on the blog!
#漏洞 前端JS框架Aurelia不安全默认值可导致XSS
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
GoSecure
24/7 managed detection, response, and expert cybersecurity services - GoSecure
We provide around-the-clock threat detection and incident response, backed by expert consulting to keep your organization secure.