
CVE-2022-30525
Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)
command-and-controlexploitationpenetration-testing+3
22

Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)


Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

CVE-2022-1388

CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell

Cleo 远程代码执行漏洞批量检测脚本(CVE-2024-50623)

Windows Print Spooler Service RCE CVE-2021-1675 (PrintNightmare)

Confluence Server and Data Center存在一个远程代码执行漏洞,未经身份验证的攻击者可以利用该漏洞向目标服务器注入恶意ONGL表达式,进而在目标服务器上执行任意代码。

Vulnerability in GNU InetUtils telnetd Enables Remote Root Access

Python exploit for CVE-2022-3218 that generates a reverse TCP payload via msfvenom and delivers it over HTTP to a target Windows host.