bug-bounty498
google349
xss301
microsoft292
facebook262
rce211
exploit199
malware169
apple161
cve136
account-takeover115
bragging-post102
privilege-escalation95
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering55
react52
access-control52
input-validation49
cross-site-scripting48
cloudflare47
aws47
web-security46
lfi46
docker46
sql-injection45
smart-contract45
ethereum44
web-application44
ctf43
oauth43
defi43
web343
node42
pentest39
open-source39
race-condition39
cloud37
idor37
info-disclosure36
burp-suite36
auth-bypass35
0
7/10
Two well-known but still exploitable RCE vulnerabilities in Atlassian products: CVE-2019-11581 in Jira's ContactAdministrators form via Java expression injection, and CVE-2019-3396 in Confluence's Widget Connector macro allowing arbitrary file access and command execution via the _template parameter. The article provides step-by-step exploitation techniques with proof-of-concept payloads.
remote-code-execution
rce
jira
confluence
atlassian
cve-2019-11581
cve-2019-3396
contact-administrators
widget-connector
java-deserialization
server-side-template-injection
exploit
bug-bounty
CVE-2019-11581
CVE-2019-3396
Jira
Confluence
Atlassian
Valeriy Shevchenko
Knownsec 404
ruvlol