#漏洞 【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
https://mp.weixin.qq.com/s/vM0pXZ5mhusFBsj1xD-2zw
Weixin Official Accounts Platform
【漏洞分析】CVE-2021-29200 Apache OFBiz RMI Bypass RCE 分析
CVE-2021-29200 Apache OFBiz RMI Bypass RCE ,通过黑名单绕过,从而造成一个反序列化远程命令执行漏洞
#漏洞 Open Distro for Elasticsearch SSRF漏洞(CVE-2021-31828)
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
https://rotem-bar.com/ssrf-in-open-distro-for-elasticsearch-cve-2021-31828?guid=none&deviceId=8277082d-b611-40d0-9c28-e15797f0ab39
My Publications
CVE-2021-31828 - SSRF in Open Distro for ElasticSearch
#漏洞 CVE‑2021‑1079 – NVIDIA GeForce Experience命令执行
https://voidsec.com/nvidia-geforce-experience-command-execution/
https://voidsec.com/nvidia-geforce-experience-command-execution/
VoidSec
CVE‑2021‑1079 - NVIDIA GeForce Experience Command Execution - VoidSec
CVE-2021-1079: NVIDIA GeForce Experience (GFE) v.<= 3.21 is affected by an Arbitrary File Write vulnerability which lead to Command Execution.
#漏洞 Cisco RV34X系列 权限提升漏洞(CVE-2021-1520)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
ONEKEY
Advisory: Cisco RV34X Series - Privilege Escalation in vpnTimer - ONEKEY
IoT Inspector detected a rare security vulnerability in Cisco's RV34X Series. Read the full root analysis on the blog!
#漏洞 前端JS框架Aurelia不安全默认值可导致XSS
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
GoSecure
24/7 managed detection, response, and expert cybersecurity services - GoSecure
We provide around-the-clock threat detection and incident response, backed by expert consulting to keep your organization secure.
#漏洞 NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket
https://blog.sonarsource.com/nosql-injections-in-rocket-chat/
https://blog.sonarsource.com/nosql-injections-in-rocket-chat/
Sonarsource
NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket
We recently discovered vulnerabilities in Rocket.Chat, a popular team communications solution, that could be used to take over Rock.Chat instances.
#漏洞 (u)rxvt terminal (+bash) remoteish code execution 0day
https://seclists.org/fulldisclosure/2021/May/33
https://seclists.org/fulldisclosure/2021/May/33
seclists.org
Full Disclosure: (u)rxvt terminal (+bash) remoteish code execution 0day
#漏洞 Vulnerability项目20210522更新了132条漏洞信息,其中部分为0day,项目地址:
https://github.com/EdgeSecurityTeam/Vulnerability
https://github.com/EdgeSecurityTeam/Vulnerability
#漏洞 WordPress XXE Vulnerability in Media Library – CVE-2021-29447
https://blog.wpsec.com/wordpress-xxe-in-media-library-cve-2021-29447/
https://blog.wpsec.com/wordpress-xxe-in-media-library-cve-2021-29447/
WPSec
WordPress XXE Vulnerability in Media Library - CVE-2021-29447 - WPSec
WordPress versions 5.7, 5.6.2, 5.6.1, 5.6, 5.0.11 are affected to XML eXternal Entity vulnerability where an authenticated user with the ability to upload files in the Media Library can upload a malicious WAVE file that could lead to remote arbitrary file…