This Metasploit module exploits untrusted serialized data processed by the WAS DMGR Server and Cells in the IBM Websphere Application Server. NOTE: There is a required 2 minute timeout between…
Exim 4.87 < 4.91 – (Local / Remote) Command Execution
Google Chrome 73.0.3683.103 – ‘WasmMemoryObject::Grow’ Use-After-Free
Zimbra < 8.8.11 – XML External Entity Injection / Server-Side Request Forgery
LibreNMS – addhost Command Injection (Metasploit)
IBM Websphere Application Server – Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)
Vim < 8.1.1365 / Neovim < 0.3.6 – Arbitrary Code Execution
Zoho ManageEngine ServiceDesk Plus 9.3 – ‘SiteLookup.do’ Cross-Site Scripting
Cisco RV130W 1.0.3.44 – Remote Stack Overflow
NUUO NVRMini 2 3.9.1 – ‘sscanf’ Stack Overflow