#漏洞 CVE-2021-30724:macOS 和 iOS 中的 CVMServer 漏洞
https://www.trendmicro.com/en_us/research/21/f/CVE-2021-30724_CVMServer_Vulnerability_in_macOS_and_iOS.html
https://www.trendmicro.com/en_us/research/21/f/CVE-2021-30724_CVMServer_Vulnerability_in_macOS_and_iOS.html
Trend Micro
CVE-2021-30724: CVMServer Vulnerability in macOS and iOS
We analyze the patched CVE-2021-30724 vulnerability, affecting macOS, iOS, and iPadOS. If exploited, this flaw can allow privilege escalation.
#漏洞 Jetty 通用 Servlets 组件 ConcatServlet 信息泄露漏洞(CVE-2021-28169)
https://github.com/vulhub/vulhub/blob/master/jetty/CVE-2021-28169/README.zh-cn.md
https://github.com/vulhub/vulhub/blob/master/jetty/CVE-2021-28169/README.zh-cn.md
GitHub
vulhub/jetty/CVE-2021-28169/README.zh-cn.md at master · vulhub/vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose - vulhub/vulhub
#漏洞 About the Unsuccessful Quest for a Deserialization Gadget (or: How I found CVE-2021-21481)
https://codewhitesec.blogspot.com/2021/06/about-unsuccessful-quest-for.html
https://codewhitesec.blogspot.com/2021/06/about-unsuccessful-quest-for.html
Blogspot
CODE WHITE | Blog: About the Unsuccessful Quest for a Deserialization Gadget (or: How I found CVE-2021-21481)
This blog post describes the research on SAP J2EE Engine 7.50 I did between October 2020 and January 2021. The first part describes how I se...
#漏洞 Citrix Application Delivery Controller访问控制错误漏洞(CVE-2020-8300)
https://github.com/stuartcarroll/CitrixADC-CVE-2020-8300
https://github.com/stuartcarroll/CitrixADC-CVE-2020-8300
GitHub
GitHub - stuartcarroll/CitrixADC-CVE-2020-8300: Detect Citrix ADC SAML action or SAML iDP Profile config vulnerable to CVE-2020…
Detect Citrix ADC SAML action or SAML iDP Profile config vulnerable to CVE-2020-8300 using Citrix ADC NITRO API - stuartcarroll/CitrixADC-CVE-2020-8300
#漏洞 Unauthenticated Gitlab SSRF
https://vin01.github.io/piptagole/gitlab/ssrf/security/2021/06/15/gitlab-ssrf.html
https://vin01.github.io/piptagole/gitlab/ssrf/security/2021/06/15/gitlab-ssrf.html
#漏洞 CVE-2021-31585: Accellion kiteworks - Web administrator to remote code execution
https://zxsecurity.co.nz/research/accellion-kiteworks-CVE-2021-31585/
https://zxsecurity.co.nz/research/accellion-kiteworks-CVE-2021-31585/
ZX Security
CVE-2021-31585: Accellion kiteworks - Web administrator to remote code execution
Introduction ZX Security performed security testing of Accellion’s kiteworks application. The review was performed with a copy of the kiteworks virtual machine (VM), as well as access to a client pre-production instance.
#漏洞 Quick Analysis for the SSID Format String Bug
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
codecolor.ist
CodeColorist
Personal notes
#漏洞 Microsoft SharePoint远程代码执行漏洞(CVE-2021-31181)
https://packetstormsecurity.com/files/163208/sharepoint_unsafe_control.rb.txt
https://packetstormsecurity.com/files/163208/sharepoint_unsafe_control.rb.txt
Packetstormsecurity
Microsoft SharePoint Unsafe Control And ViewState Remote Code Execution ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers