#漏洞 Unauthenticated Gitlab SSRF
https://vin01.github.io/piptagole/gitlab/ssrf/security/2021/06/15/gitlab-ssrf.html
https://vin01.github.io/piptagole/gitlab/ssrf/security/2021/06/15/gitlab-ssrf.html
#漏洞 CVE-2021-31585: Accellion kiteworks - Web administrator to remote code execution
https://zxsecurity.co.nz/research/accellion-kiteworks-CVE-2021-31585/
https://zxsecurity.co.nz/research/accellion-kiteworks-CVE-2021-31585/
ZX Security
CVE-2021-31585: Accellion kiteworks - Web administrator to remote code execution
Introduction ZX Security performed security testing of Accellion’s kiteworks application. The review was performed with a copy of the kiteworks virtual machine (VM), as well as access to a client pre-production instance.
#漏洞 Quick Analysis for the SSID Format String Bug
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
codecolor.ist
CodeColorist
Personal notes
#漏洞 Microsoft SharePoint远程代码执行漏洞(CVE-2021-31181)
https://packetstormsecurity.com/files/163208/sharepoint_unsafe_control.rb.txt
https://packetstormsecurity.com/files/163208/sharepoint_unsafe_control.rb.txt
Packetstormsecurity
Microsoft SharePoint Unsafe Control And ViewState Remote Code Execution ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
#漏洞 CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
Medium
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
#漏洞 CiviCRM 5.22.0 - Code Execution Vulnerability Chain Explained
https://blog.sonarsource.com/civicrm-code-execution-vulnerability-chain-explained
https://blog.sonarsource.com/civicrm-code-execution-vulnerability-chain-explained
Sonarsource
CiviCRM 5.22.0 - Code Execution Vulnerability Chain Explained
We discovered critical code vulnerabilities in CiviCRM, a popular CRM plugin for Wordpress, Joomla and Drupal. Learn more about how to find and patch these issues.
#漏洞 CVE-2021-31939
Outlook, Office • <= 16.0.13628.20274 • Use After Free
https://cpr-zero.checkpoint.com/vulns/cprid-2164/
Outlook, Office • <= 16.0.13628.20274 • Use After Free
https://cpr-zero.checkpoint.com/vulns/cprid-2164/
CPR-Zero
CPR-Zero: CVE-2021-31939
Check Point Research Vulnerability Repository
收集的一些在线工具列表:https://forum.ywhack.com/bountytips.php?tools
一些好用的在线字典系列:https://forum.ywhack.com/wordlists.php
反弹shell在线命令生成:https://forum.ywhack.com/shell.php
文件下载快捷命令生成:https://forum.ywhack.com/bountytips.php?download
工具合集/安全资料/漏洞情报:https://forum.ywhack.com/center.php
各种技巧,赏金姿势、工具等:https://forum.ywhack.com/bountytips.php
一些好用的在线字典系列:https://forum.ywhack.com/wordlists.php
反弹shell在线命令生成:https://forum.ywhack.com/shell.php
文件下载快捷命令生成:https://forum.ywhack.com/bountytips.php?download
工具合集/安全资料/漏洞情报:https://forum.ywhack.com/center.php
各种技巧,赏金姿势、工具等:https://forum.ywhack.com/bountytips.php
Ywhack
[~]#棱角 ::Edge.Forum*
#漏洞 Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE-2021-32824
https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
GitHub Security Lab
GHSL-2021-034_043: Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE…
Multiple vulnerabilities have been found in Apache Dubbo enabling attackers to compromise and run arbitrary system commands on both Dubbo consumers and providers.
#漏洞 CVE-2021-1497: CISCO HYPERFLEX HX AUTH HANDLING REMOTE COMMAND EXECUTION
https://www.zerodayinitiative.com/blog/2021/6/23/cve-2021-1497-cisco-hyperflex-hx-auth-handling-remote-command-execution
https://www.zerodayinitiative.com/blog/2021/6/23/cve-2021-1497-cisco-hyperflex-hx-auth-handling-remote-command-execution
Zero Day Initiative
Zero Day Initiative — CVE-2021-1497: Cisco HyperFlex HX Auth Handling Remote Command Execution
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Kc Udonsi and Yazhi Wang of the Trend Micro Research Team detail a recent code execution vulnerability in the Cisco HyperFlex HX Data Platform. The bug was originally discovered…
#漏洞 CVE-2021-24084 An unpatched information disclosure in Microsoft Windows
https://halove23.blogspot.com/2021/06/CVE-2021-24084-Unpatched-ID.html
https://halove23.blogspot.com/2021/06/CVE-2021-24084-Unpatched-ID.html
#漏洞 A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.
https://github.com/kahla-sec/CVE-2021-27850_POC
https://github.com/kahla-sec/CVE-2021-27850_POC
GitHub
GitHub - kahla-sec/CVE-2021-27850_POC: A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated…
A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution. - kahla-sec/CVE-2021-27850_POC