#漏洞 runc mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs (CVE-2021-30465)
http://blog.champtar.fr/runc-symlink-CVE-2021-30465/
http://blog.champtar.fr/runc-symlink-CVE-2021-30465/
#漏洞 Dubbo Consumer脚本注入RCE - CVE-2021-30181
https://threedr3am.github.io/2021/05/30/Dubbo%20Consumer%E8%84%9A%E6%9C%AC%E6%B3%A8%E5%85%A5RCE%20-%20CVE-2021-30181/#more
https://threedr3am.github.io/2021/05/30/Dubbo%20Consumer%E8%84%9A%E6%9C%AC%E6%B3%A8%E5%85%A5RCE%20-%20CVE-2021-30181/#more
大彩笔threedr3am
Dubbo Consumer脚本注入RCE - CVE-2021-30181
0x00 事情的由来昨天看到Dubbo公布了几个新的CVE,一个没有Credit的中危 CVE-2021-25641,一个有Credit(Github Security Lab)的低危 CVE-2021-30181,其中CVE-2021-30181漏洞邮件标题为“RCE on customers via Script route poisoning (Nashorn script injectio
#漏洞 \QNAP Music Station/Malware Remover未授权远程代码执行漏洞(CVE-2020-36197 CVE-2020-36198)
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/
Shielder
Shielder - QNAP MusicStation/MalwareRemover Pre-Auth Remote Code Execution
QNAP MusicStation and MalwareRemover pre-installed official apps are affected by an arbitrary file upload and a command injection, leading to pre-auth remote root command execution.
#漏洞 Overwolf 1-Click Remote Code Execution - CVE-2021-33501
https://swordbytes.com/blog/security-advisory-overwolf-1-click-remote-code-execution-cve-2021-33501/
https://swordbytes.com/blog/security-advisory-overwolf-1-click-remote-code-execution-cve-2021-33501/
Overwolf 1-Click Remote Code Execution - CVE-2021-33501 | SwordBytes Security
SwordBytes researchers have identified an Unauthenticated Remote Code Execution (RCE) vulnerability in Overwolf’s Client Application by abusing a Reflected Cross-Site Scripting (XSS) issue present in the “overwolfstore://” URL handler. This vulnerability…
#漏洞 Vcenter Server CVE-2021-21985 RCE PAYLOAD
https://www.iswin.org/2021/06/02/Vcenter-Server-CVE-2021-21985-RCE-PAYLOAD/
https://www.iswin.org/2021/06/02/Vcenter-Server-CVE-2021-21985-RCE-PAYLOAD/
随风'S Blog
Vcenter Server CVE-2021-21985 RCE PAYLOAD
废话不多讲,老外对补丁的分析,具体补丁的分析和漏洞点可以看这篇文章 https://attackerkb.com/topics/X85GKjaVER/cve-2021-21985 这个漏洞主要是对Spring 管理的bean进行相关的方法对象操作,但是这里不同的是,操作的bean在内存中基本上都是一个对象,这样就可以通过多次方法调用来实现伪链式调用。 Vcenter 开启Debug端口,可以直
#漏洞 Apache Solr 8.8.1 SSRF to Arbitrary File Write Vulnerability
http://noahblog.360.cn/apache-solr-8-8-1-ssrf-to-file-write/
http://noahblog.360.cn/apache-solr-8-8-1-ssrf-to-file-write/
root@cyberworld:~# Noah Lab
Apache Solr 8.8.1 SSRF to Arbitrary File Write Vulnerability
0x01. TL; DR事情要从 Skay 的 SSRF 漏洞(CVE-2021-27905)说起。正巧后续的工作中遇到了 Solr,我就接着这个漏洞进行了进一步的分析。漏洞原因是在于 Solr 主从复制(Replication)时,可以传入任意 URL,而 Solr 会针对此 URL 进行请求。 说起主从复制,那么对于 Redis 主从复制漏洞比较熟悉的人会知道,可以利用主从复制的功能实现任意文件写入,那么 Solr 是否会存在这个问题呢?通过进一步的分析,我发现这个漏洞岂止于 SSRF,简直就是 Redis…
#漏洞 Vulnerability Spotlight: A deep dive into macOS SMB server
https://blog.talosintelligence.com/2021/06/vuln-spotlight-smb-mac-deep-dive.html
https://blog.talosintelligence.com/2021/06/vuln-spotlight-smb-mac-deep-dive.html
Cisco Talos Blog
Vulnerability Spotlight: A deep dive into macOS SMB server
By Aleksandar Nikolich.
Executive summary
Cisco Talos recently discovered multiple vulnerabilities in macOS’s implementation of SMB server. An adversary could exploit these vulnerabilities to carry out a variety of malicious actions, including revealing…
Executive summary
Cisco Talos recently discovered multiple vulnerabilities in macOS’s implementation of SMB server. An adversary could exploit these vulnerabilities to carry out a variety of malicious actions, including revealing…
#漏洞 CVE-2021-31181: MICROSOFT SHAREPOINT WEBPART INTERPRETATION CONFLICT REMOTE CODE EXECUTION VULNERABILITY
https://www.zerodayinitiative.com/blog/2021/6/1/cve-2021-31181-microsoft-sharepoint-webpart-interpretation-conflict-remote-code-execution-vulnerability
https://www.zerodayinitiative.com/blog/2021/6/1/cve-2021-31181-microsoft-sharepoint-webpart-interpretation-conflict-remote-code-execution-vulnerability
Zero Day Initiative
Zero Day Initiative — CVE-2021-31181: Microsoft SharePoint WebPart Interpretation Conflict Remote Code Execution Vulnerability
In May of 2021, Microsoft released a patch to correct CVE-2021-31181 – a remote code execution bug in the supported versions of Microsoft SharePoint Server. This bug was reported to the ZDI program by an anonymous researcher and is also known as ZDI-21…
#漏洞 利用 Apple Safari 中的 0Day WebAssembly 漏洞 (CVE-2021-30734)
https://blog.ret2.io/2021/06/02/pwn2own-2021-jsc-exploit/
https://blog.ret2.io/2021/06/02/pwn2own-2021-jsc-exploit/
RET2 Systems Blog
32 bits, 32 gigs, 1 click...
In this post we will examine a vulnerability in the WebAssembly subsystem of JavaScriptCore, the JavaScript engine used in WebKit and Apple Safari. The issue...
#漏洞 CVE-2021–22201:在 Gitlab 上读取任意文件
https://tradahacking.vn/cve-2021-22201-arbitrary-file-read-on-gitlab-d84d77cd83e3
https://tradahacking.vn/cve-2021-22201-arbitrary-file-read-on-gitlab-d84d77cd83e3
#漏洞 CVE-2020-27301 - CVE-2020-27302: Realtek Critical Wi-Fi Vulnerabilities, elevated privileges and hijack wireless communications
https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day
https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day