writeups.xyz writeups.xyz / OS Command Injection

Title Vulnerabilities Programs Authors
Hacking a Secure Industrial Remote Access Gateway
SSD Advisory – SonicWall SMA100 Stored XSS To RCE
Getting Unauthenticated Remote Code Execution On The Logsign Unified Secops Platform
Exploiting Steam: Usual and Unusual Ways in the CEF Framework
Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes
Wikimedia/svgtranslate 2.0.1 Remote Code Execution
20 Security Issues Found in Xiaomi Devices
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
BatBadBut: You can't securely execute commands on Windows
CVE-2024-1212: Unauthenticated Command Injection In Progress Kemp LoadMaster
OpenNMS Vulnerabilities: Securing Code against Attackers’ Unexpected Ways
Exploiting embedded mitel phones for unauthenticated remote code execution
A christmas tale: pwning GTB Central Console (CVE-2024-22107 & CVE-2024-22108)
High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE (CVE-2023-46805 & CVE-2024-21887)
Nokia vBMC — BMC Log Scanner Remote Code Execution
SSH ProxyCommand == unexpected code execution (CVE-2023-51385)
OS Command Injection in cPH2 Charging Station <2.0.0 (CVE-2023-46359 and CVE-2023-46360)
Technical Advisory – Multiple Vulnerabilities in Nagios XI
pfSense Security: Sensing Code Vulnerabilities with SonarCloud
It's not a Feature, It's a Vulnerability
CVE-2023-37927 & CVE-2023-37928 - Multiple post-auth blind OS command and Python code injection vulnerabilities in Zyxel’s NAS326 devices
CVE-2023-4473 & CVE-2023-4474 - Authentication bypass and multiple blind OS command injection vulnerabilities in Zyxel’s NAS326 devices
Uncovering a Command Injection, $2400 Bounty
[CVE-2023–38743] ManageEngine ADManager Command Injection
Rooting Xiaomi WiFi Routers