当前位置:网站首页>Sorting out of key vulnerabilities identified by CMS in the peripheral management of red team (I)

Sorting out of key vulnerabilities identified by CMS in the peripheral management of red team (I)

2022-06-24 03:11:00 xiaochuhe.


  One 、 Open source operation and maintenance monitoring

( One )Jenkins

  • Jenkins Path traversal arbitrary file write vulnerability (CVE-2019-10352)
  • Jenkins Git client Plug in Command Execution Vulnerability (CVE-2019-10392)
  • Jenkins Historical exploiter —— Sploitus | Exploit & Hacktool Search Engine

( Two )Zabbix

  • CVE-2020-11800 Zabbix Remote code execution vulnerability
  • Zabbix Medium CSRF To RCE(CVE-2021-27927)
  • Zabbix 2.2 - 3.0.3 Remote code execution vulnerability
  • Zabbix Agent 3.0.1 mysql.size shell Command injection (CVE-2016-4338)
  • Zabbix Historical exploiter —— Sploitus | Exploit & Hacktool Search Engine

( 3、 ... and )Nagios

  • Nagios XI 5.6.9 Remote code execution vulnerability (CVE-2019-20197)
  • nagios-xi-5.7.5 Multiple vulnerabilities (CVE-2021-25296~99)
  • Nagios Code injection vulnerability (CVE-2021-3273)
  • Nagios XI 5.5.10: XSS to RCE
  • Nagios Historical exploiter —— Sploitus | Exploit & Hacktool Search Engine


  Two 、 database

MDAT A variety of mainstream database attack tools

( One )Mysql

  • Mysql Raise the right (CVE-2016-6663、CVE-2016-6664 Combined practice )
  • Mysql Summary of database penetration and vulnerability utilization
  • Mysql Into the album
  • Higher version MySQL And UDF Raise the right
  • Mysql A collection of historical loopholes —— Sploitus | Exploit & Hacktool Search Engine

Sploitus | Exploit & Hacktool Search Engine

 ( Two )Mssql

( 3、 ... and )Redis


  3、 ... and 、OA System

( One ) Pan Wei (Weaver-Ecology-OA)

( Two ) Zhiyuan (Seeyon)

( 3、 ... and ) Kingdee OA(Kingdee OA)

Kingdee collaborative office system GETSHELL Loophole ——https://www.seebug.org/vuldb/ssvid-93826

( Four ) Accessible OA(TongDa OA)

原网站

版权声明
本文为[xiaochuhe.]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/02/202202211643347169.html