#漏洞 Vulnerability项目20210522更新了132条漏洞信息,其中部分为0day,项目地址:
https://github.com/EdgeSecurityTeam/Vulnerability
https://github.com/EdgeSecurityTeam/Vulnerability
#漏洞 WordPress XXE Vulnerability in Media Library – CVE-2021-29447
https://blog.wpsec.com/wordpress-xxe-in-media-library-cve-2021-29447/
https://blog.wpsec.com/wordpress-xxe-in-media-library-cve-2021-29447/
WPSec
WordPress XXE Vulnerability in Media Library - CVE-2021-29447 - WPSec
WordPress versions 5.7, 5.6.2, 5.6.1, 5.6, 5.0.11 are affected to XML eXternal Entity vulnerability where an authenticated user with the ability to upload files in the Media Library can upload a malicious WAVE file that could lead to remote arbitrary file…
#漏洞 VMware ESXi OpenSLP堆溢出漏洞(CVE-2021-21974)
https://github.com/straightblast/My-PoC-Exploits/blob/master/CVE-2021-21974.py
https://github.com/straightblast/My-PoC-Exploits/blob/master/CVE-2021-21974.py
GitHub
My-PoC-Exploits/CVE-2021-21974.py at master · straightblast/My-PoC-Exploits
PoC exploits I wrote. They're as is and I will not offer support - straightblast/My-PoC-Exploits
#漏洞 SolarWinds Orion 反序列化到 RCE(CVE-2021-31474)
https://testbnull.medium.com/ph%C3%A2n-t%C3%ADch-l%E1%BB%97-h%E1%BB%95ng-solarwinds-orion-deserialization-to-rce-cve-2021-31474-b31a5f168bf0
https://testbnull.medium.com/ph%C3%A2n-t%C3%ADch-l%E1%BB%97-h%E1%BB%95ng-solarwinds-orion-deserialization-to-rce-cve-2021-31474-b31a5f168bf0
Medium
Phân tích lỗ hổng SolarWinds Orion Deserialization to RCE (CVE-2021–31474)
Sau 2 tháng trời diff patch Exchange thì tới patch của tháng 5 này thì mình đã bị ngộ độc và quá chán nản,
#漏洞 nginx DNS Resolver Off-by-One Heap Write Vulnerability - CVE-2021-23017
https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
X41 D-Sec - Penetration Tests and Source Code Audits
nginx DNS Resolver Off-by-One Heap Write Vulnerability
An off-by-one error in ngx_resolver_copy() while processing DNS responses allows a network attacker to write a dot character (‘.’, 0x2E) out of bounds in a heap allocated buffer.
#漏洞 CVE-2021-33564 Argument Injection in Ruby Dragonfly
https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
zxsecurity.co.nz
Ruby Dragonfly - ZX Security
Full spectrum IT security services
#漏洞 Pulse Connect Secure 任意代码执行漏洞(CVE-2021-22908)
https://github.com/CERTCC/PoC-Exploits/blob/master/cve-2021-22908/cve-2021-22908.py
https://github.com/CERTCC/PoC-Exploits/blob/master/cve-2021-22908/cve-2021-22908.py
GitHub
PoC-Exploits/cve-2021-22908/cve-2021-22908.py at master · CERTCC/PoC-Exploits
Select proof-of-concept exploits for software vulnerabilities to aid in identifying and testing vulnerable systems. - CERTCC/PoC-Exploits
#漏洞 Signedness issue in ClassInfo message handler leads to RCE on CS:GO client
https://hackerone.com/reports/876719
https://hackerone.com/reports/876719
HackerOne
Valve disclosed on HackerOne: Signedness issue in ClassInfo message...
Title: Signedness issue in ClassInfo message handler leads to RCE on CS:GO client
Scope: csgo.exe
Weakness: Array Index Underflow
Severity: Critical (9.6)
Link: ...
Scope: csgo.exe
Weakness: Array Index Underflow
Severity: Critical (9.6)
Link: ...
#漏洞 CVE-2021-31440: AN INCORRECT BOUNDS CALCULATION IN THE LINUX KERNEL EBPF VERIFIER
https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier
https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier
Zero Day Initiative
Zero Day Initiative — CVE-2021-31440: An Incorrect Bounds Calculation in the Linux Kernel eBPF Verifier
In April 2021, the ZDI received a Linux kernel submission that turned out to be an incorrect bounds calculation bug in the extended Berkeley Packet Filter (eBPF) verifier. This bug was submitted to the program by Manfred Paul ( @_manfp ) of the RedRocket…
#漏洞 QNAP MalwareRemover 命令注入漏洞(CVE-2020-36198)
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
Shielder
Shielder - QNAP MusicStation/MalwareRemover Pre-Auth Remote Code Execution
QNAP MusicStation and MalwareRemover pre-installed official apps are affected by an arbitrary file upload and a command injection, leading to pre-auth remote root command execution.
#漏洞 VMware vCenter Server 远程代码执行漏洞(CVE-2021-21985)
https://attackerkb.com/topics/X85GKjaVER/cve-2021-21985
https://attackerkb.com/topics/X85GKjaVER/cve-2021-21985
AttackerKB
CVE-2021-21985 | AttackerKB
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enab…
#漏洞 PLAYING WITH IMAGETRAGICK LIKE IT'S 2016
https://www.synacktiv.com/en/publications/playing-with-imagetragick-like-its-2016.html
https://www.synacktiv.com/en/publications/playing-with-imagetragick-like-its-2016.html
Synacktiv
Playing with ImageTragick like it's 2016
You probably already have encountered document converting features that deal with ImageMagick during engagements but for some reason you were not able to exploit them. This article will mention some t