#漏洞 CVE-2021-31181: MICROSOFT SHAREPOINT WEBPART INTERPRETATION CONFLICT REMOTE CODE EXECUTION VULNERABILITY
https://www.zerodayinitiative.com/blog/2021/6/1/cve-2021-31181-microsoft-sharepoint-webpart-interpretation-conflict-remote-code-execution-vulnerability
https://www.zerodayinitiative.com/blog/2021/6/1/cve-2021-31181-microsoft-sharepoint-webpart-interpretation-conflict-remote-code-execution-vulnerability
Zero Day Initiative
Zero Day Initiative — CVE-2021-31181: Microsoft SharePoint WebPart Interpretation Conflict Remote Code Execution Vulnerability
In May of 2021, Microsoft released a patch to correct CVE-2021-31181 – a remote code execution bug in the supported versions of Microsoft SharePoint Server. This bug was reported to the ZDI program by an anonymous researcher and is also known as ZDI-21…
#漏洞 利用 Apple Safari 中的 0Day WebAssembly 漏洞 (CVE-2021-30734)
https://blog.ret2.io/2021/06/02/pwn2own-2021-jsc-exploit/
https://blog.ret2.io/2021/06/02/pwn2own-2021-jsc-exploit/
RET2 Systems Blog
32 bits, 32 gigs, 1 click...
In this post we will examine a vulnerability in the WebAssembly subsystem of JavaScriptCore, the JavaScript engine used in WebKit and Apple Safari. The issue...
#漏洞 CVE-2021–22201:在 Gitlab 上读取任意文件
https://tradahacking.vn/cve-2021-22201-arbitrary-file-read-on-gitlab-d84d77cd83e3
https://tradahacking.vn/cve-2021-22201-arbitrary-file-read-on-gitlab-d84d77cd83e3
#漏洞 CVE-2020-27301 - CVE-2020-27302: Realtek Critical Wi-Fi Vulnerabilities, elevated privileges and hijack wireless communications
https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day
https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day
#漏洞 CVE-2021-30724:macOS 和 iOS 中的 CVMServer 漏洞
https://www.trendmicro.com/en_us/research/21/f/CVE-2021-30724_CVMServer_Vulnerability_in_macOS_and_iOS.html
https://www.trendmicro.com/en_us/research/21/f/CVE-2021-30724_CVMServer_Vulnerability_in_macOS_and_iOS.html
Trend Micro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We analyze the patched CVE-2021-30724 vulnerability, affecting macOS, iOS, and iPadOS. If exploited, this flaw can allow privilege escalation.
#漏洞 Jetty 通用 Servlets 组件 ConcatServlet 信息泄露漏洞(CVE-2021-28169)
https://github.com/vulhub/vulhub/blob/master/jetty/CVE-2021-28169/README.zh-cn.md
https://github.com/vulhub/vulhub/blob/master/jetty/CVE-2021-28169/README.zh-cn.md
GitHub
vulhub/jetty/CVE-2021-28169/README.zh-cn.md at master · vulhub/vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose - vulhub/vulhub
#漏洞 About the Unsuccessful Quest for a Deserialization Gadget (or: How I found CVE-2021-21481)
https://codewhitesec.blogspot.com/2021/06/about-unsuccessful-quest-for.html
https://codewhitesec.blogspot.com/2021/06/about-unsuccessful-quest-for.html
Blogspot
CODE WHITE | Blog: About the Unsuccessful Quest for a Deserialization Gadget (or: How I found CVE-2021-21481)
This blog post describes the research on SAP J2EE Engine 7.50 I did between October 2020 and January 2021. The first part describes how I se...