๐จ CVE-2021-26716
Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.
๐@cveNotify
Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.
๐@cveNotify
GitHub
XSS Vulnerability ยท Issue #1652 ยท emoncms/emoncms
Hi, I have found a XSS in vulnerability in: emoncms/Modules/input/Views/schedule.php using the parameter 'node' Proof of concept exploit: http://127.0.0.1:9000/Modules/input/Views/s...
๐จ CVE-2021-27516
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
๐@cveNotify
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
๐@cveNotify
GitHub
fix(parse): treat backslash as forwardslash in scheme delimiter ยท medialize/URI.js@a1ad8bc
make `https:/\attacker.com` like `https:\/attacker.com` result in `https://attacker.com/`
๐จ CVE-2021-27515
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
๐@cveNotify
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
๐@cveNotify
GitHub
[security] More backslash fixes (#197) ยท unshiftio/url-parse@d1e7e88
Small footprint URL parser that works seamlessly across Node.js and browser environments. - unshiftio/url-parse
๐จ CVE-2021-27514
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
๐@cveNotify
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).
๐@cveNotify
GitHub
ArianeBlow/exploit-eyesofnetwork5.3.10
Contribute to ArianeBlow/exploit-eyesofnetwork5.3.10 development by creating an account on GitHub.
๐จ CVE-2021-27513
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
๐@cveNotify
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
๐@cveNotify
GitHub
ArianeBlow/exploit-eyesofnetwork5.3.10
Contribute to ArianeBlow/exploit-eyesofnetwork5.3.10 development by creating an account on GitHub.
๐จ CVE-2020-35499
A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when using BT_SNDMTU/BT_RCVMTU for SCO sockets. This could allow a local attacker with a special user privilege to crash the system (DOS) or leak kernel internal information.
๐@cveNotify
A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when using BT_SNDMTU/BT_RCVMTU for SCO sockets. This could allow a local attacker with a special user privilege to crash the system (DOS) or leak kernel internal information.
๐@cveNotify
๐จ CVE-2020-12283
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
๐@cveNotify
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
๐@cveNotify
๐จ CVE-2020-12049
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
๐@cveNotify
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
๐@cveNotify
๐จ CVE-2020-13163
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
๐@cveNotify
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
๐@cveNotify
GitHub
Security vulnerability: missing SSL hostname validation ยท Issue #25 ยท ConradIrwin/em-imap
GitHub Security Lab (GHSL) Vulnerability Report: GHSL-2020-095 The GitHub Security Lab team has identified potential security vulnerabilities in em-imap. We are committed to working with you to hel...
๐จ CVE-2020-13482
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
๐@cveNotify
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
๐@cveNotify
GitHub
Security vulnerability: missing SSL hostname validation ยท Issue #339 ยท igrigorik/em-http-request
GitHub Security Lab (GHSL) Vulnerability Report: GHSL-2020-094 Summary Missing hostname validation allows an attacker to perform a man in the middle attack against users of the library. Product em-...
๐จ CVE-2020-13445
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.
๐@cveNotify
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.
๐@cveNotify
๐จ CVE-2018-16621
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
๐@cveNotify
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
๐@cveNotify
Github
GHSL-2020-015: Remote Code Execution - Bypass of CVE-2018-16621 mitigations in Nexus Repository Manager - GitHub Security Lab
High privileged users can bypass the existing mitigations and inject arbitrary Java EL expressions in Nexus Repository Manager, leading to a Remote Code Execution (RCE) vulnerability.
๐จ CVE-2019-20788
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
๐@cveNotify
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
๐@cveNotify
๐จ CVE-2020-27998
An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.
๐@cveNotify
An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.
๐@cveNotify
GitHub
FastReports/FastReport
Free Open Source Reporting tool for .NET5/.NET Core/.NET Framework that helps your application generate document-like reports - FastReports/FastReport
๐จ CVE-2020-29529
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
๐@cveNotify
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
๐@cveNotify
GitHub
hashicorp/go-slug
The slug package provides functions to create slug archives - hashicorp/go-slug
๐จ CVE-2021-26119
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
๐@cveNotify
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
๐@cveNotify
GitHub
smarty/CHANGELOG.md at master ยท smarty-php/smarty
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. - smarty-php/smarty
๐จ CVE-2021-24115
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
๐@cveNotify
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
๐@cveNotify
๐จ CVE-2021-3149
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.
๐@cveNotify
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.
๐@cveNotify
๐จ CVE-2021-26120
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
๐@cveNotify
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
๐@cveNotify
GitHub
smarty/CHANGELOG.md at master ยท smarty-php/smarty
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. - smarty-php/smarty
๐จ CVE-2020-35128
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.
๐@cveNotify
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.
๐@cveNotify
Mautic Forums
Announcements
Important announcements - only administrators and moderators have write-access to this category.
๐จ CVE-2020-35571
An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on CSP settings.
๐@cveNotify
An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on CSP settings.
๐@cveNotify