#漏洞 Cisco RV34X系列 权限提升漏洞(CVE-2021-1520)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-series-privilege-escalation-vpntimer/
ONEKEY
Advisory: Cisco RV34X Series - Privilege Escalation in vpnTimer - ONEKEY
IoT Inspector detected a rare security vulnerability in Cisco's RV34X Series. Read the full root analysis on the blog!
#漏洞 前端JS框架Aurelia不安全默认值可导致XSS
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/
GoSecure
24/7 managed detection, response, and expert cybersecurity services - GoSecure
We provide around-the-clock threat detection and incident response, backed by expert consulting to keep your organization secure.
#漏洞 NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket
https://blog.sonarsource.com/nosql-injections-in-rocket-chat/
https://blog.sonarsource.com/nosql-injections-in-rocket-chat/
Sonarsource
NoSQL Injections in Rocket.Chat 3.12.1: How A Small Leak Grounds A Rocket
We recently discovered vulnerabilities in Rocket.Chat, a popular team communications solution, that could be used to take over Rock.Chat instances.
#漏洞 (u)rxvt terminal (+bash) remoteish code execution 0day
https://seclists.org/fulldisclosure/2021/May/33
https://seclists.org/fulldisclosure/2021/May/33
seclists.org
Full Disclosure: (u)rxvt terminal (+bash) remoteish code execution 0day
#漏洞 Vulnerability项目20210522更新了132条漏洞信息,其中部分为0day,项目地址:
https://github.com/EdgeSecurityTeam/Vulnerability
https://github.com/EdgeSecurityTeam/Vulnerability
#漏洞 WordPress XXE Vulnerability in Media Library – CVE-2021-29447
https://blog.wpsec.com/wordpress-xxe-in-media-library-cve-2021-29447/
https://blog.wpsec.com/wordpress-xxe-in-media-library-cve-2021-29447/
WPSec
WordPress XXE Vulnerability in Media Library - CVE-2021-29447 - WPSec
WordPress versions 5.7, 5.6.2, 5.6.1, 5.6, 5.0.11 are affected to XML eXternal Entity vulnerability where an authenticated user with the ability to upload files in the Media Library can upload a malicious WAVE file that could lead to remote arbitrary file…
#漏洞 VMware ESXi OpenSLP堆溢出漏洞(CVE-2021-21974)
https://github.com/straightblast/My-PoC-Exploits/blob/master/CVE-2021-21974.py
https://github.com/straightblast/My-PoC-Exploits/blob/master/CVE-2021-21974.py
GitHub
My-PoC-Exploits/CVE-2021-21974.py at master · straightblast/My-PoC-Exploits
PoC exploits I wrote. They're as is and I will not offer support - straightblast/My-PoC-Exploits
#漏洞 SolarWinds Orion 反序列化到 RCE(CVE-2021-31474)
https://testbnull.medium.com/ph%C3%A2n-t%C3%ADch-l%E1%BB%97-h%E1%BB%95ng-solarwinds-orion-deserialization-to-rce-cve-2021-31474-b31a5f168bf0
https://testbnull.medium.com/ph%C3%A2n-t%C3%ADch-l%E1%BB%97-h%E1%BB%95ng-solarwinds-orion-deserialization-to-rce-cve-2021-31474-b31a5f168bf0
Medium
Phân tích lỗ hổng SolarWinds Orion Deserialization to RCE (CVE-2021–31474)
Sau 2 tháng trời diff patch Exchange thì tới patch của tháng 5 này thì mình đã bị ngộ độc và quá chán nản,
#漏洞 nginx DNS Resolver Off-by-One Heap Write Vulnerability - CVE-2021-23017
https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
X41 D-Sec - Penetration Tests and Source Code Audits
nginx DNS Resolver Off-by-One Heap Write Vulnerability
An off-by-one error in ngx_resolver_copy() while processing DNS responses allows a network attacker to write a dot character (‘.’, 0x2E) out of bounds in a heap allocated buffer.
#漏洞 CVE-2021-33564 Argument Injection in Ruby Dragonfly
https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
zxsecurity.co.nz
Ruby Dragonfly - ZX Security
Full spectrum IT security services