CVE-2018-6574
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
Github link:
https://github.com/faqihudin13/CVE-2018-6574
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
Github link:
https://github.com/faqihudin13/CVE-2018-6574
GitHub
GitHub - faqihudin13/CVE-2018-6574: CVE-2018-6574: go get
CVE-2018-6574: go get. Contribute to faqihudin13/CVE-2018-6574 development by creating an account on GitHub.
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Github link:
https://github.com/qlusec/CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Github link:
https://github.com/qlusec/CVE-2019-10149
GitHub
GitHub - qlusec/CVE-2019-10149: test POC for CVE-2019-10149
test POC for CVE-2019-10149. Contribute to qlusec/CVE-2019-10149 development by creating an account on GitHub.