#漏洞 Jetty 通用 Servlets 组件 ConcatServlet 信息泄露漏洞(CVE-2021-28169)
https://github.com/vulhub/vulhub/blob/master/jetty/CVE-2021-28169/README.zh-cn.md
https://github.com/vulhub/vulhub/blob/master/jetty/CVE-2021-28169/README.zh-cn.md
GitHub
vulhub/jetty/CVE-2021-28169/README.zh-cn.md at master · vulhub/vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose - vulhub/vulhub
#漏洞 About the Unsuccessful Quest for a Deserialization Gadget (or: How I found CVE-2021-21481)
https://codewhitesec.blogspot.com/2021/06/about-unsuccessful-quest-for.html
https://codewhitesec.blogspot.com/2021/06/about-unsuccessful-quest-for.html
Blogspot
CODE WHITE | Blog: About the Unsuccessful Quest for a Deserialization Gadget (or: How I found CVE-2021-21481)
This blog post describes the research on SAP J2EE Engine 7.50 I did between October 2020 and January 2021. The first part describes how I se...
#漏洞 Citrix Application Delivery Controller访问控制错误漏洞(CVE-2020-8300)
https://github.com/stuartcarroll/CitrixADC-CVE-2020-8300
https://github.com/stuartcarroll/CitrixADC-CVE-2020-8300
GitHub
GitHub - stuartcarroll/CitrixADC-CVE-2020-8300: Detect Citrix ADC SAML action or SAML iDP Profile config vulnerable to CVE-2020…
Detect Citrix ADC SAML action or SAML iDP Profile config vulnerable to CVE-2020-8300 using Citrix ADC NITRO API - stuartcarroll/CitrixADC-CVE-2020-8300
#漏洞 Unauthenticated Gitlab SSRF
https://vin01.github.io/piptagole/gitlab/ssrf/security/2021/06/15/gitlab-ssrf.html
https://vin01.github.io/piptagole/gitlab/ssrf/security/2021/06/15/gitlab-ssrf.html
#漏洞 CVE-2021-31585: Accellion kiteworks - Web administrator to remote code execution
https://zxsecurity.co.nz/research/accellion-kiteworks-CVE-2021-31585/
https://zxsecurity.co.nz/research/accellion-kiteworks-CVE-2021-31585/
ZX Security
CVE-2021-31585: Accellion kiteworks - Web administrator to remote code execution
Introduction ZX Security performed security testing of Accellion’s kiteworks application. The review was performed with a copy of the kiteworks virtual machine (VM), as well as access to a client pre-production instance.
#漏洞 Quick Analysis for the SSID Format String Bug
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
codecolor.ist
CodeColorist
Personal notes
#漏洞 Microsoft SharePoint远程代码执行漏洞(CVE-2021-31181)
https://packetstormsecurity.com/files/163208/sharepoint_unsafe_control.rb.txt
https://packetstormsecurity.com/files/163208/sharepoint_unsafe_control.rb.txt
Packetstormsecurity
Microsoft SharePoint Unsafe Control And ViewState Remote Code Execution ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
#漏洞 CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
Medium
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
#漏洞 CiviCRM 5.22.0 - Code Execution Vulnerability Chain Explained
https://blog.sonarsource.com/civicrm-code-execution-vulnerability-chain-explained
https://blog.sonarsource.com/civicrm-code-execution-vulnerability-chain-explained
Sonarsource
CiviCRM 5.22.0 - Code Execution Vulnerability Chain Explained
We discovered critical code vulnerabilities in CiviCRM, a popular CRM plugin for Wordpress, Joomla and Drupal. Learn more about how to find and patch these issues.
#漏洞 CVE-2021-31939
Outlook, Office • <= 16.0.13628.20274 • Use After Free
https://cpr-zero.checkpoint.com/vulns/cprid-2164/
Outlook, Office • <= 16.0.13628.20274 • Use After Free
https://cpr-zero.checkpoint.com/vulns/cprid-2164/
CPR-Zero
CPR-Zero: CVE-2021-31939
Check Point Research Vulnerability Repository
收集的一些在线工具列表:https://forum.ywhack.com/bountytips.php?tools
一些好用的在线字典系列:https://forum.ywhack.com/wordlists.php
反弹shell在线命令生成:https://forum.ywhack.com/shell.php
文件下载快捷命令生成:https://forum.ywhack.com/bountytips.php?download
工具合集/安全资料/漏洞情报:https://forum.ywhack.com/center.php
各种技巧,赏金姿势、工具等:https://forum.ywhack.com/bountytips.php
一些好用的在线字典系列:https://forum.ywhack.com/wordlists.php
反弹shell在线命令生成:https://forum.ywhack.com/shell.php
文件下载快捷命令生成:https://forum.ywhack.com/bountytips.php?download
工具合集/安全资料/漏洞情报:https://forum.ywhack.com/center.php
各种技巧,赏金姿势、工具等:https://forum.ywhack.com/bountytips.php
Ywhack
[~]#棱角 ::Edge.Forum*
#漏洞 Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE-2021-32824
https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
GitHub Security Lab
GHSL-2021-034_043: Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE…
Multiple vulnerabilities have been found in Apache Dubbo enabling attackers to compromise and run arbitrary system commands on both Dubbo consumers and providers.