1Panel vulnerable to ommand injection when entering the container terminal

### Impact The authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. 1. Vulnerability analysis. ``` backendappapiv1terminal.go#Contai ...

Continue Reading
1Panel vulnerable to ommand injection when entering the container terminal

### Impact The authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. 1. Vulnerability analysis. ``` backendappapiv1terminal.go#Contai ...

Continue Reading
Gorilla WebSocket vulnerability

## Releases * Ubuntu 18.04 ESM * Ubuntu 16.04 ESM ## Packages * golang-websocket - Go package implementing the WebSocket protocol It was discovered that Gorilla WebSocket incorrectly handled dec ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Uncaught Exception in engine.io

### Impact A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. > RangeError: Invalid WebSocket frame: RSV2 and RSV3 must be ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Improper Access Control in Onionshare

Between September 26, 2021 and October 8, 2021, [Radically Open Security](https://www.radicallyopensecurity.com/) conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund's [ ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Security Bulletin: IBM UrbanCode Release is affected by CVE-2020-13935

## Summary IBM UrbanCode Release version 6.2.2.7 - 6.2.4 are affected by CVE-2020-13935 ## Vulnerability Details ** CVEID: **[CVE-2020-13935]() ** DESCRIPTION: **Apache Tomcat is vulnerable to a denia ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

IDACode – An Integration For IDA And VS Code Which Connects Both To Easily Execute And Debug IDAPython Scripts

[![](https://4.bp.blogspot.com/-P5OdKM3AnzM/Yd0b-NXgU9I/AAAAAAAA8a0/Rld1093WLHssqXYXYPpzyIIQ3c2QSrkjACK4BGAYYCw/w640-h360/idacode_2_preview-767772.gif)]() IDACode makes it easy to execute and debug Py ...

Continue Reading
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump

This module uses a blind SQL injection (CVE-2020-5724) affecting the Grandstream UCM62xx IP PBX to dump the users table. The injection occurs over a websocket at the websockify endpoint, and specifica ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Back to Main

Subscribe for the latest news: