authenticated-rce

2 articles
sort: new top best
clear filter
0 3/10

Veeam released patches for 7 critical vulnerabilities in Backup & Replication software, including CVE-2026-21666 (CVSS 9.9) allowing authenticated domain users to achieve remote code execution on the Backup Server.

Veeam CVE-2026-21666 CVE-2026-21667
thehackernews.com · [email protected] (The Hacker News) · 16 hours ago · details
0 8/10

A detailed walkthrough of discovering a critical SQL injection vulnerability (CVE-2019-17602) in Zoho OpManager through white-box analysis by decompiling JAR files, analyzing web.xml servlet mappings, and tracing control flow to identify unsafe dynamic SQL query construction in the getAllMOs method. The vulnerability allows authenticated remote code execution via stacked queries and PostgreSQL UDF commands.

CVE-2019-17602 Zoho OpManager ManageEngine OpManager OPMDeviceDetailsServlet frycos PostgreSQL
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details