Menu
  • About
  • Contact Us

Month: March 2022

CVE-2022-24990: TerraMaster TOS unauthenticated remote command execution via PHP Object Instantiation

March 7, 2022
 |  No Comments
 |  Uncategorized

Introduction This report explains how researchers at Octagon Networks were able to chain two interesting vulnerabilities to achieve unauthenticated remote command […]

Read More →

CVE-2022-24948: Apache JSPWiki preauth Stored XSS to ATO

March 2, 2022
 |  No Comments
 |  Uncategorized

Apache JSPWiki is a leading open source Wiki engine, feature-rich and built around standard JEE components (Java, servlets, JSP), according to […]

Read More →

Recent Posts

  • Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities
  • Bypass CSP Using WordPress By Abusing Same Origin Method Execution
  • CVE-2022-24990: TerraMaster TOS unauthenticated remote command execution via PHP Object Instantiation
  • CVE-2022-24948: Apache JSPWiki preauth Stored XSS to ATO
  • MAMP Server preauth XSS leading to Host Compromise (0day)

Archives

  • October 2022
  • May 2022
  • March 2022
  • January 2022

Categories

  • bug bounty, rce, preauth rce,
  • Uncategorized