rce

102 articles
Sort: New Top Best
clear filter
0
rce
strynx.org · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
rce
hawkinsecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
rce
mohamedharon.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0

Research demonstrating a complete RCE attack chain on DeskPro helpdesk software through multiple chained vulnerabilities: insufficient API access control (leaking JWT secrets and admin config), and insecure deserialization in the template editor. The exploit was demonstrated against Bitdefender's support center, achieving remote code execution from an unauthenticated user registration.

CVE-2020-11465 CVE-2020-11463 CVE-2020-11466 CVE-2020-11464 CVE-2020-11467 DeskPro Bitdefender osTicket Kayako PHP Live! Freelancer Inc Redforce Web Security
blog.redforce.io · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0

An RCE vulnerability was discovered via Rack's ShowExceptions middleware being enabled in production, which leaked the Rails secret token used to sign cookies. The attacker used this token to forge authenticated cookies and execute arbitrary commands on the server.

Rack Rails ShowExceptions action_dispatch.secret_token secret_token.rb robertheaton.com
sites.google.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0 1/10

A brief mention of a $36,000 bug bounty for a remote code execution vulnerability in Google App Engine, but with no technical details provided.

Google Google App Engine
sites.google.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability
rce
rezo.blog · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0

A Jenkins instance was found vulnerable to RCE due to improper access control, allowing unauthenticated users to gain admin access via GitHub OAuth and execute arbitrary Groovy scripts. The vulnerability was discovered during subdomain enumeration and responsibly disclosed to the organization's CTO.

Jenkins GitHub DoSomething.org MuhammadKhizerJaved nahamsec Matt HackerOne Bugcrowd
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
blog.harshjaiswal.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
poc-server.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0

A researcher discovered an unauthenticated Apache Solr instance running on a Microsoft subdomain vulnerable to CVE-2019-17558, exploitable via velocity template injection to achieve RCE. The attack requires modifying the params.Resource.Loader.Enabled configuration and then sending a malicious velocity template payload.

CVE-2019-17558 Microsoft Apache Solr tide90.microsoft.com Muhammad Khizer Javed
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
rce
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
bug-bounty

A bug bounty researcher discovered RCE on an abandoned staging web service via an unauthenticated PUT HTTP method that allowed arbitrary file uploads, enabling PHP web shell deployment and subsequent internal network traversal with privilege escalation through credential reuse and weak security practices.

nmap ncat netcat PHP Python SSH RDP SMB DNS zone transfer
blog.zsec.uk · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
rce
blog.orange.tw · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
rce
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
rce
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
rce
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
More