<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel xmlns:content="http://purl.org/rss/1.0/modules/content/"><title>Seebug</title><link>https://www.seebug.org/rss.xml</link><description>赋予漏洞灵魂</description><atom:link href="https://www.seebug.org/rss.xml" rel="self"></atom:link><language>zh-cn</language><lastBuildDate>Mon, 10 Apr 2017 22:16:51 -0000</lastBuildDate><item><title>Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability (CVE-2017-3881)</title><link>https://www.seebug.org/vuldb/ssvid-92932</link><description>
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
</description><guid>https://www.seebug.org/vuldb/ssvid-92932</guid><content:encoded>
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
</content:encoded><level>8</level><category>代码执行</category><updated_date>2017-04-10 14:10:26</updated_date></item><item><title>Apache Struts ClassLoader Manipulation Remote Code Execution</title><link>https://www.seebug.org/vuldb/ssvid-86388</link><description>Apache Struts是美国阿帕奇（Apache）软件基金会负责维护的一款用于创建企业级Java Web应用的开源框架。</description><guid>https://www.seebug.org/vuldb/ssvid-86388</guid><content:encoded>Apache Struts是美国阿帕奇（Apache）软件基金会负责维护的一款用于创建企业级Java Web应用的开源框架。</content:encoded><level>9</level><category>其他类型</category><updated_date>2017-04-10 07:52:30</updated_date></item><item><title>dnaLIMS Code Execution / XSS / Traversal / Session Hijacking （CVE-2017-6526）</title><link>https://www.seebug.org/vuldb/ssvid-92931</link><description> </description><guid>https://www.seebug.org/vuldb/ssvid-92931</guid><content:encoded> </content:encoded><level>7</level><category>命令执行</category><updated_date>2017-04-10 06:33:41</updated_date></item><item><title>iOS/macOS Remote code execution triggered by malformed GIF in ImageIO framework（CVE-2017-2416）</title><link>https://www.seebug.org/vuldb/ssvid-92924</link><description>ImageIO Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later

A memory corruption issue was addressed through improved input validation.</description><guid>https://www.seebug.org/vuldb/ssvid-92924</guid><content:encoded>ImageIO Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later

A memory corruption issue was addressed through improved input validation.</content:encoded><level>8</level><category>代码执行</category><updated_date>2017-04-10 04:39:39</updated_date></item><item><title>PHPCMS 注册页面任意文件上传漏洞</title><link>https://www.seebug.org/vuldb/ssvid-92930</link><description>PHPCMS 注册页面任意文件上传漏洞</description><guid>https://www.seebug.org/vuldb/ssvid-92930</guid><content:encoded>PHPCMS 注册页面任意文件上传漏洞</content:encoded><level>8</level><category>文件上传</category><updated_date>2017-04-10 04:27:38</updated_date></item><item><title>PHPCMS v9 wap模块 SQL注入</title><link>https://www.seebug.org/vuldb/ssvid-92929</link><description>PHPCMS v9 wap模块 SQL注入</description><guid>https://www.seebug.org/vuldb/ssvid-92929</guid><content:encoded>PHPCMS v9 wap模块 SQL注入</content:encoded><level>8</level><category>SQL 注入</category><updated_date>2017-04-10 03:06:21</updated_date></item><item><title>Win32k 特权提升漏洞（MS16-135）(CVE-2016-7255)</title><link>https://www.seebug.org/vuldb/ssvid-92530</link><description>如果 Windows 内核模式驱动程序无法正确处理内存中对象，则会存在多个特权提升漏洞。成功利用此漏洞的攻击者可以在内核模式下运行任意代码。攻击者可随后安装程序；查看、更改或删除数据；或者创建拥有完全用户权限的新帐户。

攻击者必须先登录系统，然后才能利用这些漏洞。然后攻击者可以运行一个为利用这些漏洞而经特殊设计的应用程序，从而控制受影响的系统。该更新通过更正 Windows 内核模式驱动程序处理内存中对象的方式来解决这些漏洞。</description><guid>https://www.seebug.org/vuldb/ssvid-92530</guid><content:encoded>如果 Windows 内核模式驱动程序无法正确处理内存中对象，则会存在多个特权提升漏洞。成功利用此漏洞的攻击者可以在内核模式下运行任意代码。攻击者可随后安装程序；查看、更改或删除数据；或者创建拥有完全用户权限的新帐户。

攻击者必须先登录系统，然后才能利用这些漏洞。然后攻击者可以运行一个为利用这些漏洞而经特殊设计的应用程序，从而控制受影响的系统。该更新通过更正 Windows 内核模式驱动程序处理内存中对象的方式来解决这些漏洞。</content:encoded><level>8</level><category>权限提升</category><updated_date>2017-04-10 01:54:25</updated_date></item><item><title>Xen: broken check in memory_exchange() permits PV guest breakout（CVE-2017-7228）</title><link>https://www.seebug.org/vuldb/ssvid-92927</link><description> This bug report describes a vulnerability in memory_exchange() that
permits PV guest kernels to write to an arbitrary virtual address with
hypervisor privileges. The vulnerability was introduced through a
broken fix for CVE-2012-5513 / XSA-29.</description><guid>https://www.seebug.org/vuldb/ssvid-92927</guid><content:encoded> This bug report describes a vulnerability in memory_exchange() that
permits PV guest kernels to write to an arbitrary virtual address with
hypervisor privileges. The vulnerability was introduced through a
broken fix for CVE-2012-5513 / XSA-29.</content:encoded><level>8</level><category>其他类型</category><updated_date>2017-04-09 04:54:07</updated_date></item><item><title>e107 CMS 2.1.1 权限提升漏洞</title><link>https://www.seebug.org/vuldb/ssvid-92531</link><description>Datas from $_POST['updated_data'] inside usersettings.php are not properly validated so we can set user_admin value in database using this input.

Version 2.1.2 Released issue still not fixed</description><guid>https://www.seebug.org/vuldb/ssvid-92531</guid><content:encoded>Datas from $_POST['updated_data'] inside usersettings.php are not properly validated so we can set user_admin value in database using this input.

Version 2.1.2 Released issue still not fixed</content:encoded><level>8</level><category>权限提升</category><updated_date>2017-04-08 13:55:24</updated_date></item><item><title>DjangoUEditor 1.9.143 任意文件上传漏洞</title><link>https://www.seebug.org/vuldb/ssvid-92826</link><description>DjangoUeditor是将百度开发的富文本编辑器Ueditor移植到Django中的组件，它的使用率还是相当高的。经笔者测试，即便是现在可以下载使用的1.9.143版本中，依然存在着这个漏洞。</description><guid>https://www.seebug.org/vuldb/ssvid-92826</guid><content:encoded>DjangoUeditor是将百度开发的富文本编辑器Ueditor移植到Django中的组件，它的使用率还是相当高的。经笔者测试，即便是现在可以下载使用的1.9.143版本中，依然存在着这个漏洞。</content:encoded><level>8</level><category>文件上传</category><updated_date>2017-04-08 12:05:03</updated_date></item><item><title>semcms /semcms/view.php 参数ID 注入漏洞</title><link>https://www.seebug.org/vuldb/ssvid-92926</link><description>semcms /semcms/view.php 参数ID 注入漏洞 </description><guid>https://www.seebug.org/vuldb/ssvid-92926</guid><content:encoded>semcms /semcms/view.php 参数ID 注入漏洞 </content:encoded><level>7</level><category>SQL 注入</category><updated_date>2017-04-08 11:14:51</updated_date></item><item><title>Serv-U FTP/MFT Server Unauthenticated Privilege Escalation</title><link>https://www.seebug.org/vuldb/ssvid-92912</link><description>
"Monitor and configure your Serv-U deployment from anywhere through our advanced
web management console. No special applications are required to administrate
your server and access is protected with highly secure HTTPS." - https://www.serv-u.com

</description><guid>https://www.seebug.org/vuldb/ssvid-92912</guid><content:encoded>
"Monitor and configure your Serv-U deployment from anywhere through our advanced
web management console. No special applications are required to administrate
your server and access is protected with highly secure HTTPS." - https://www.serv-u.com

</content:encoded><level>8</level><category>权限提升</category><updated_date>2017-04-07 08:48:07</updated_date></item><item><title>熊海CMS v1.0 后台登录绕过漏洞</title><link>https://www.seebug.org/vuldb/ssvid-92925</link><description>熊海CMS v1.0 后台登录绕过漏洞</description><guid>https://www.seebug.org/vuldb/ssvid-92925</guid><content:encoded>熊海CMS v1.0 后台登录绕过漏洞</content:encoded><level>8</level><category>登录绕过</category><updated_date>2017-04-07 06:54:47</updated_date></item><item><title>WebKit: UXSS via a focus event and a link element (CVE-2017-2479)</title><link>https://www.seebug.org/vuldb/ssvid-92922</link><description>This is somewhat similar to https://crbug.com/663476.
</description><guid>https://www.seebug.org/vuldb/ssvid-92922</guid><content:encoded>This is somewhat similar to https://crbug.com/663476.
</content:encoded><level>8</level><category>跨站脚本</category><updated_date>2017-04-07 06:08:51</updated_date></item><item><title>WebKit: UXSS via a synchronous page load（CVE-2017-2480）</title><link>https://www.seebug.org/vuldb/ssvid-92923</link><description>Here's a snippet of the method SubframeLoader::requestFrame which is invoked when the |src| of an iframe object is changed.</description><guid>https://www.seebug.org/vuldb/ssvid-92923</guid><content:encoded>Here's a snippet of the method SubframeLoader::requestFrame which is invoked when the |src| of an iframe object is changed.</content:encoded><level>8</level><category>跨站脚本</category><updated_date>2017-04-07 03:35:56</updated_date></item><item><title>WebKit: Use-after-free in JSC::B3::Procedure::resetReachability（CVE-2017-2470）</title><link>https://www.seebug.org/vuldb/ssvid-92921</link><description>Note: It seems it doesn't crash the JSC compiled without Address Sanitizer.
</description><guid>https://www.seebug.org/vuldb/ssvid-92921</guid><content:encoded>Note: It seems it doesn't crash the JSC compiled without Address Sanitizer.
</content:encoded><level>8</level><category>释放后重用</category><updated_date>2017-04-07 03:22:47</updated_date></item><item><title>WebKit: Use-After-Free via Document::adoptNode (CVE-2017-2468)</title><link>https://www.seebug.org/vuldb/ssvid-92920</link><description>This is a regression test from: https://crbug.com/541206.
But I think it seems not possible to turn it into an UXSS in WebKit.
</description><guid>https://www.seebug.org/vuldb/ssvid-92920</guid><content:encoded>This is a regression test from: https://crbug.com/541206.
But I think it seems not possible to turn it into an UXSS in WebKit.
</content:encoded><level>8</level><category>跨站脚本</category><updated_date>2017-04-07 03:19:37</updated_date></item><item><title>WebKit: heap-buffer-overflow in JSC::SymbolTableEntry::isWatchable (CVE-2017-2469)</title><link>https://www.seebug.org/vuldb/ssvid-92919</link><description>I confirmed the PoC crashes the release version of Safari 10.0.3(12602.4.8).
(It might need to refresh the page several times.)</description><guid>https://www.seebug.org/vuldb/ssvid-92919</guid><content:encoded>I confirmed the PoC crashes the release version of Safari 10.0.3(12602.4.8).
(It might need to refresh the page several times.)</content:encoded><level>8</level><category>缓冲区溢出</category><updated_date>2017-04-07 03:16:42</updated_date></item><item><title>QNAP QTS multiple RCE vulnerabilities (CVE-2017-6361, CVE-2017-6360, CVE-2017-6359)</title><link>https://www.seebug.org/vuldb/ssvid-92918</link><description>The latest version of this advisory is available at:
https://sintonen.fi/advisories/qnap-qts-multiple-rce-vulnerabilities.txt  </description><guid>https://www.seebug.org/vuldb/ssvid-92918</guid><content:encoded>The latest version of this advisory is available at:
https://sintonen.fi/advisories/qnap-qts-multiple-rce-vulnerabilities.txt  </content:encoded><level>7</level><category>其他类型</category><updated_date>2017-04-07 02:05:52</updated_date></item><item><title>Wordpress Plugin Firewall 2 CSRF/储存型XSS漏洞</title><link>https://www.seebug.org/vuldb/ssvid-92917</link><description> </description><guid>https://www.seebug.org/vuldb/ssvid-92917</guid><content:encoded> </content:encoded><level>7</level><category>其他类型</category><updated_date>2017-04-07 01:55:41</updated_date></item></channel></rss>