ReadyAPI 2.5.0 / 2.6.0 – Remote Code Execution

Post ContentRead More ...

Continue Reading
CVE-2018-20580

The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.Read More ...

Continue Reading
??????HTTP?.NET Remoting finding and using deserialization vulnerability-vulnerability warning-the black bar safety net

One, overview In the NCC Group and most recent safety assessment, ??????.NET v2. 0 app, ???????.NET Remoting by HTTP to send the SOAP request to the other server to communicate. In the application of ...

Continue Reading
Kentico CMS Staging SyncServer Unserialize Remote Command Execution

This module exploits a vulnerability in the Kentico CMS platform versions 12.0.14 and earlier. Remote Command Execution is possible via unauthenticated XML requests to the Staging Service SyncServer.a ...

Continue Reading
Kentico CMS Staging SyncServer Unserialize Remote Command Execution

This module exploits a vulnerability in the Kentico CMS platform versions 12.0.14 and earlier. Remote Command Execution is possible via unauthenticated XML requests to the Staging Service SyncServer.a ...

Continue Reading
U.S. Dept Of Defense: SharePoint Web Services Exposed to Anonymous Access Users

**Summary:** Any unauthenticated/anonymous users are able to access the SharePoint Web Services (.wsdl files) for the ????? Initiative website. **Description:** The SharePoint installation for this pa ...

Continue Reading
SmartClient 120 Information Disclosure / XML Injection / LFI / Code Execution

Post ContentRead More ...

Continue Reading
Huawei EulerOS: Security Advisory for java-1.7.0-openjdk (EulerOS-SA-2017-1208)

The remote host is missing an update for the Huawei EulerOSRead More ...

Continue Reading

Back to Main

Subscribe for the latest news: