🚨 CVE-2021-3177
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
🎖@cveNotify
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
🎖@cveNotify
🚨 CVE-2021-23240
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
🎖@cveNotify
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
🎖@cveNotify
🚨 CVE-2020-20294
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
🎖@cveNotify
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
🎖@cveNotify
GitHub
Vulnerability Report: cmswing 1.3.8 code execution · Issue #49 · arterli/CmsWing
Find a code execution vulnerability in cmswing project version 1.3.8,Details can be found in the analysis below. The vulnerability lies in the log function in the cmswing/src/mode/action.js async l...
🚨 CVE-2021-21287
MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability. The target application may have functionality for importing data from a URL, publishing data to a URL, or otherwise reading data from a URL that can be tampered with. The attacker modifies the calls to this functionality by supplying a completely different URL or by manipulating how URLs are built (path traversal etc.). In a Server-Side Request Forgery (SSRF) attack, the attacker can abuse functionality on the server to read or update internal resources. The attacker can supply or modify a URL which the code running on the server will read or submit data, and by carefully selecting the URLs, the attacker may be able to read server configuration such as AWS metadata, connect to internal services like HTTP enabled databases, or perform post requests towards internal services which are not intended to be exposed. This is fixed in version RELEASE.2021-01-30T00-20-58Z, all users are advised to upgrade. As a workaround you can disable the browser front-end with "MINIO_BROWSER=off" environment variable.
🎖@cveNotify
MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability. The target application may have functionality for importing data from a URL, publishing data to a URL, or otherwise reading data from a URL that can be tampered with. The attacker modifies the calls to this functionality by supplying a completely different URL or by manipulating how URLs are built (path traversal etc.). In a Server-Side Request Forgery (SSRF) attack, the attacker can abuse functionality on the server to read or update internal resources. The attacker can supply or modify a URL which the code running on the server will read or submit data, and by carefully selecting the URLs, the attacker may be able to read server configuration such as AWS metadata, connect to internal services like HTTP enabled databases, or perform post requests towards internal services which are not intended to be exposed. This is fixed in version RELEASE.2021-01-30T00-20-58Z, all users are advised to upgrade. As a workaround you can disable the browser front-end with "MINIO_BROWSER=off" environment variable.
🎖@cveNotify
GitHub
fix: LoginSTS should be an inline implementation (#11337) · minio/minio@eb6871e
STS tokens can be obtained by using local APIs
once the remote JWT token is presented, current
code was not validating the incoming token in the
first place and was incorrectly making a network ...
once the remote JWT token is presented, current
code was not validating the incoming token in the
first place and was incorrectly making a network ...
🚨 CVE-2020-21176
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
🎖@cveNotify
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
🎖@cveNotify
blog.jiguang.xyz
thinkjs - sql注入漏洞分析 · 极光 - 再见已是故人
Vulnerability Report: Thinkjs Blind SQL Injection 本文档描述了Thinkjs project的一个盲注漏洞,由于关系数据库中model.increment(field, step) 和 model.decrement(field, step)函数对step的参数缺少检查,恶意的参数可以导致程序在处
🚨 CVE-2020-21180
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
🎖@cveNotify
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
🎖@cveNotify
GitHub
koa2-blog v1.0.0 sql injection vulnerability · Issue #41 · wunci/Koa2-blog
A sql injection was discovered in koa2-blog 1.0.0 .There is a sql injection vulnerability which allows remote attackers to Injecting a malicious SQL statement into a server via: post http://127.0.0...
🚨 CVE-2020-20290
Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory traversal vulnerability.
🎖@cveNotify
Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory traversal vulnerability.
🎖@cveNotify
🚨 CVE-2020-20295
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
🎖@cveNotify
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
🎖@cveNotify
GitHub
Vulnerability Report: cmswing 1.3.8 updateAction sql injection · Issue #50 · arterli/CmsWing
Find a code execution vulnerability in cmswing project version 1.3.8,Details can be found in the analysis below. Vulnerability Location The vulnerability lies in the updateAction function in the cm...
🚨 CVE-2020-25036
UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command.
🎖@cveNotify
UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command.
🎖@cveNotify
Globadis works
Ucopia V6 : Multiple CVE used to root the host
Ucopia V6 : Multiple CVE used to root the host - Globadis works.
🚨 CVE-2020-1896
A stack overflow vulnerability in Facebook Hermes ‘builtin apply’ prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.com/facebook/hermes/commit/86543ac47e59c522976b5632b8bf9a2a4583c7d2) allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
🎖@cveNotify
A stack overflow vulnerability in Facebook Hermes ‘builtin apply’ prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.com/facebook/hermes/commit/86543ac47e59c522976b5632b8bf9a2a4583c7d2) allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
🎖@cveNotify
GitHub
Added stack overflow check for hermes::vm:: hermesBuiltinApply · facebook/hermes@86543ac
Summary: This adds a missing check for stack overflow.
Reviewed By: tmikov
Differential Revision: D20104955
fbshipit-source-id: 1f37e23d2e28ebcd3aa4176d134b8418e7059ebd
Reviewed By: tmikov
Differential Revision: D20104955
fbshipit-source-id: 1f37e23d2e28ebcd3aa4176d134b8418e7059ebd
🚨 CVE-2020-24335
An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corrupt memory with crafted DNS packets.
🎖@cveNotify
An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corrupt memory with crafted DNS packets.
🎖@cveNotify
GitHub
GitHub - adamdunkels/uip: The historical uIP sources
The historical uIP sources. Contribute to adamdunkels/uip development by creating an account on GitHub.
🚨 CVE-2020-28495
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.
🎖@cveNotify
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.
🎖@cveNotify
🚨 CVE-2020-28494
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option shell set to true and because the type parameter is not properly sanitized.
🎖@cveNotify
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option shell set to true and because the type parameter is not properly sanitized.
🎖@cveNotify
GitHub
Fixed "Command Injection" in `image.stream()` - thank to Sam Sanoop. · totaljs/framework@6192491
Node.js framework. Contribute to totaljs/framework development by creating an account on GitHub.
🚨 CVE-2020-8101
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issue affects: ADT LifeShield DIY HD Video Doorbell version 1.0.02R09 and prior versions.
🎖@cveNotify
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issue affects: ADT LifeShield DIY HD Video Doorbell version 1.0.02R09 and prior versions.
🎖@cveNotify
Bitdefender Labs
Cracking the LifeShield: Unauthorized Live-Streaming in your Home
Also, CVE-2020-8101 - Command execution due to unsanitized input Do-it-yourself home security solutions are centerpieces of the modern lifestyle. From sensors to surveillance and... #ADT #Lifeshield
🚨 CVE-2020-25506
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
🎖@cveNotify
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
🎖@cveNotify
Gist
Disclosure of vulnerabilities in D-LInk DNS320
Disclosure of vulnerabilities in D-LInk DNS320 . GitHub Gist: instantly share code, notes, and snippets.
🚨 CVE-2021-26271
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
🎖@cveNotify
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
🎖@cveNotify
GitHub
ckeditor4/CHANGES.md at major · ckeditor/ckeditor4
The best enterprise-grade WYSIWYG editor. Fully customizable with countless features and plugins. - ckeditor4/CHANGES.md at major · ckeditor/ckeditor4
🚨 CVE-2021-26272
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
🎖@cveNotify
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
🎖@cveNotify
GitHub
ckeditor4/CHANGES.md at major · ckeditor/ckeditor4
The best enterprise-grade WYSIWYG editor. Fully customizable with countless features and plugins. - ckeditor4/CHANGES.md at major · ckeditor/ckeditor4
🚨 CVE-2020-24549
openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
🎖@cveNotify
openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
🎖@cveNotify
Exploit Database
openMAINT 1.1-2.4.2 - Arbitrary File Upload
openMAINT 1.1-2.4.2 - Arbitrary File Upload.. webapps exploit for JSON platform
🚨 CVE-2020-28194
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.
🎖@cveNotify
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.
🎖@cveNotify
GitHub
radius: sanity check for vendor attribute length · accel-ppp/accel-ppp@e9d369a
High performance PPTP/L2TP/SSTP/PPPoE/IPoE server for Linux - accel-ppp/accel-ppp
🚨 CVE-2020-18568
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
🎖@cveNotify
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
🎖@cveNotify
Gist
Disclosure of vulnerabilities in D-Link DSR-250 DSR-1000N router.md
Disclosure of vulnerabilities in D-Link DSR-250 DSR-1000N router.md - Disclosure of vulnerabilities in D-Link DSR-250 DSR-1000N router.md
🚨 CVE-2021-25312
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.
🎖@cveNotify
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.
🎖@cveNotify