CODE WHITE | Red Teaming & Attack Surface Management https://code-white.com/ Recent updates on CODE WHITE [blog] and [public vulnerability list] Hugo -- gohugo.io Page("CODE WHITE | Red Teaming & Attack Surface Management") Thu, 15 Jan 2026 00:00:00 +0000 [Vulnerability] AuthenticationServiceForceResetPassword Missing Authentication in SmarterMail public-vulnerability-list/#authenticationserviceforceresetpassword-missing-authentication-in-smartermail Thu, 15 Jan 2026 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticationserviceforceresetpassword-missing-authentication-in-smartermail/ <no value> [Vulnerability] SystemAdminSettingsControllerConnectToHub Missing Authentication in SmarterMail public-vulnerability-list/#systemadminsettingscontrollerconnecttohub-missing-authentication-in-smartermail Thu, 15 Jan 2026 00:00:00 +0000 https://code-white.com/public-vulnerability-list/systemadminsettingscontrollerconnecttohub-missing-authentication-in-smartermail/ <no value> [Blog] Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive https://code-white.com/blog/2026-01-nsm-rce/ Tue, 13 Jan 2026 12:11:59 +0000 https://code-white.com/blog/2026-01-nsm-rce/ NetSupport Manager is a remote control and support software that we find surprisingly often utilized in sensitive *Operational Technology (OT)* environments, such as production plant networks. Besides describing two 0-day vulnerabilities that we found in the client component of the software, we also walk you through an exploit odyssey to finally gain unauthenticated Remote Code Execution. [Vulnerability] Multiple Vulnerabilities in ABL90 FLEX PLUS public-vulnerability-list/#multiple-vulnerabilities-in-abl90-flex-plus Wed, 17 Dec 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/multiple-vulnerabilities-in-abl90-flex-plus/ <no value> [Vulnerability] Multiple Vulnerabilities in NetSupport Manager public-vulnerability-list/#multiple-vulnerabilities-in-netsupport-manager Mon, 03 Nov 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/multiple-vulnerabilities-in-netsupport-manager/ <no value> [Blog] A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS https://code-white.com/blog/wsus-cve-2025-59287-analysis/ Wed, 29 Oct 2025 00:00:00 +0000 https://code-white.com/blog/wsus-cve-2025-59287-analysis/ How the n-day research for a suspected vulnerability in Microsoft WSUS (CVE-2025-59287) led to the surprising discovery of a new `SoapFormatter` vulnerability added by the Patch Tuesday updates of October 2025. [Vulnerability] Reporting Web Service ReportingEvent SoapFormatter Deserialization in Windows Server Update Services (WSUS) public-vulnerability-list/#reporting-web-service-reportingevent-soapformatter-deserialization-in-windows-se Thu, 23 Oct 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/reporting-web-service-reportingevent-soapformatter-deserialization-in-windows-se/ <no value> [Vulnerability] Mount Service Deserialization via NET Remoting Client in Backup & Replication public-vulnerability-list/#mount-service-deserialization-via-net-remoting-client-in-backup-replication Tue, 14 Oct 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/mount-service-deserialization-via-net-remoting-client-in-backup-replication/ <no value> [Vulnerability] Local Privilege Escalation in Intensive Care Manager (ICM) public-vulnerability-list/#local-privilege-escalation-in-intensive-care-manager-icm Mon, 21 Jul 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/local-privilege-escalation-in-intensive-care-manager-icm/ <no value> [Vulnerability] Multiple Vulnerabilities in OnlineSuite public-vulnerability-list/#multiple-vulnerabilities-in-onlinesuite Mon, 23 Jun 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/multiple-vulnerabilities-in-onlinesuite/ <no value> [Vulnerability] Remote Code Execution via Deserialization of Untrusted Data in Backup & Replication public-vulnerability-list/#remote-code-execution-via-deserialization-of-untrusted-data-in-backup-replicat Tue, 17 Jun 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/remote-code-execution-via-deserialization-of-untrusted-data-in-backup-replicat/ <no value> [Vulnerability] Unauthenticated Remote Code Execution via Deserialization of Untrusted Data in mediDOK public-vulnerability-list/#unauthenticated-remote-code-execution-via-deserialization-of-untrusted-data-in-m Wed, 14 May 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-via-deserialization-of-untrusted-data-in-m/ <no value> [Blog] Analyzing the Attack Surface of Ivanti's DSM https://code-white.com/blog/ivanti-desktop-and-server-management/ Mon, 12 May 2025 12:00:00 +0000 https://code-white.com/blog/ivanti-desktop-and-server-management/ Ivanti's Desktop & Server Management (DSM) product is an old acquaintance that we have encountered in numerous red team and internal assessments. The main purpose of the product is the centralized distribution of software packages. In our blog post *Analyzing the Attack Surface of Ivanti's DSM* we take a look at the software from an attacker's perspective. We discuss common misconfigurations, uncover the technical details of two vulnerabilities we identified and provide recommendations to harden existing DSM environments. [Vulnerability] Multiple Vulnerabilities in GFI MailEssentials public-vulnerability-list/#multiple-vulnerabilities-in-gfi-mailessentials Tue, 29 Apr 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/multiple-vulnerabilities-in-gfi-mailessentials/ <no value> [Vulnerability] Unauthenticated ServerSide TemplateInjection in Metazo public-vulnerability-list/#unauthenticated-serverside-templateinjection-in-metazo Mon, 28 Apr 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-serverside-templateinjection-in-metazo/ <no value> [Vulnerability] DefaultResourceLocator Absolute Path Traversal in ActiveReports.NET public-vulnerability-list/#defaultresourcelocator-absolute-path-traversal-in-activereports-net Tue, 25 Feb 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/defaultresourcelocator-absolute-path-traversal-in-activereports-net/ <no value> [Vulnerability] ReportFileResolver Absolute Path Traversal in Telerik Reporting public-vulnerability-list/#reportfileresolver-absolute-path-traversal-in-telerik-reporting Wed, 12 Feb 2025 00:00:00 +0000 https://code-white.com/public-vulnerability-list/reportfileresolver-absolute-path-traversal-in-telerik-reporting/ <no value> [Vulnerability] SPThemeBackgroundImageUri Relative Path Traversal in SharePoint public-vulnerability-list/#spthemebackgroundimageuri-relative-path-traversal-in-sharepoint Tue, 10 Dec 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/spthemebackgroundimageuri-relative-path-traversal-in-sharepoint/ <no value> [Vulnerability] Multiple Vulnerabilities in Syncfusion ASP.NET MVC public-vulnerability-list/#multiple-vulnerabilities-in-syncfusion-asp-net-mvc Sat, 30 Nov 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/multiple-vulnerabilities-in-syncfusion-asp-net-mvc/ <no value> [Vulnerability] Unauthenticated Remote Code Execution via Known View State Secret in FieldPie public-vulnerability-list/#unauthenticated-remote-code-execution-via-known-view-state-secret-in-fieldpie Thu, 28 Nov 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-via-known-view-state-secret-in-fieldpie/ <no value> [Vulnerability] SequenceExternalizable Arbitrary Deserialization in WebLogic Server public-vulnerability-list/#sequenceexternalizable-arbitrary-deserialization-in-weblogic-server Tue, 15 Oct 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sequenceexternalizable-arbitrary-deserialization-in-weblogic-server/ <no value> [Vulnerability] EntityDataSource Insecure Type Resolution in Telerik Report Server public-vulnerability-list/#entitydatasource-insecure-type-resolution-in-telerik-report-server Wed, 25 Sep 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/entitydatasource-insecure-type-resolution-in-telerik-report-server/ <no value> [Vulnerability] EntityDataSource Insecure Type Resolution in Telerik Reporting public-vulnerability-list/#entitydatasource-insecure-type-resolution-in-telerik-reporting Wed, 25 Sep 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/entitydatasource-insecure-type-resolution-in-telerik-reporting/ <no value> [Vulnerability] Insecure Expression Evaluation in Telerik Reporting public-vulnerability-list/#insecure-expression-evaluation-in-telerik-reporting Wed, 25 Sep 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/insecure-expression-evaluation-in-telerik-reporting/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in Backup & Replication public-vulnerability-list/#unauthenticated-remote-code-execution-in-backup-replication Wed, 04 Sep 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-backup-replication/ <no value> [Vulnerability] Unauthenticated Content Injection in OpenEdge Management public-vulnerability-list/#unauthenticated-content-injection-in-openedge-management Fri, 30 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-content-injection-in-openedge-management/ <no value> [Vulnerability] Accessible Logs in Spectrum public-vulnerability-list/#accessible-logs-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/accessible-logs-in-spectrum/ <no value> [Vulnerability] Authenticated XXE in Spectrum public-vulnerability-list/#authenticated-xxe-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-xxe-in-spectrum/ <no value> [Vulnerability] Authentication Bypass in Spectrum public-vulnerability-list/#authentication-bypass-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authentication-bypass-in-spectrum/ <no value> [Vulnerability] Deserialization of Untrusted Data in Spectrum public-vulnerability-list/#deserialization-of-untrusted-data-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/deserialization-of-untrusted-data-in-spectrum/ <no value> [Vulnerability] HardCoded not changable credentials in Spectrum public-vulnerability-list/#hardcoded-not-changable-credentials-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/hardcoded-not-changable-credentials-in-spectrum/ <no value> [Vulnerability] Serverside Request Forgery TestDataServiceRequest in Spectrum public-vulnerability-list/#serverside-request-forgery-testdataservicerequest-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/serverside-request-forgery-testdataservicerequest-in-spectrum/ <no value> [Vulnerability] Serverside Request Forgery testDeviceConnection in Spectrum public-vulnerability-list/#serverside-request-forgery-testdeviceconnection-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/serverside-request-forgery-testdeviceconnection-in-spectrum/ <no value> [Vulnerability] Unprotected JMX Registry in Spectrum public-vulnerability-list/#unprotected-jmx-registry-in-spectrum Thu, 22 Aug 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unprotected-jmx-registry-in-spectrum/ <no value> [Blog] Teaching the Old .NET Remoting New Exploitation Tricks https://code-white.com/blog/teaching-the-old-net-remoting-new-exploitation-tricks/ Wed, 31 Jul 2024 00:00:00 +0200 https://code-white.com/blog/teaching-the-old-net-remoting-new-exploitation-tricks/ This blog post provides insights into three exploitation techniques that can still be used in cases of a hardened .NET Remoting server with `TypeFilterLevel.Low` and Code Access Security (CAS) restrictions in place. Two of these tricks are considered novel and can help in cases where ExploitRemotingService is stuck. [Vulnerability] UnknownTypeResolver Insecure Type Resolution in Telerik Report Server public-vulnerability-list/#unknowntyperesolver-insecure-type-resolution-in-telerik-report-server Wed, 10 Jul 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unknowntyperesolver-insecure-type-resolution-in-telerik-report-server/ <no value> [Vulnerability] UnknownTypeResolver Insecure Type Resolution in Telerik Reporting public-vulnerability-list/#unknowntyperesolver-insecure-type-resolution-in-telerik-reporting Wed, 10 Jul 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unknowntyperesolver-insecure-type-resolution-in-telerik-reporting/ <no value> [Vulnerability] PreAuth Insecure Deserialization in Dynamics 365 Business Central public-vulnerability-list/#preauth-insecure-deserialization-in-dynamics-365-business-central Tue, 11 Jun 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/preauth-insecure-deserialization-in-dynamics-365-business-central/ <no value> [Vulnerability] BinarySerializerVulnerabilityFilter Bypass in Service Provider Console public-vulnerability-list/#binaryserializervulnerabilityfilter-bypass-in-service-provider-console Tue, 28 May 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/binaryserializervulnerabilityfilter-bypass-in-service-provider-console/ <no value> [Vulnerability] Insecure NET Remoting in Project Center Server public-vulnerability-list/#insecure-net-remoting-in-project-center-server Mon, 22 Apr 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/insecure-net-remoting-in-project-center-server/ <no value> [Vulnerability] Unauthenticated SQL Injection in Smartfactory Shopfloor.guide public-vulnerability-list/#unauthenticated-sql-injection-in-smartfactory-shopfloor-guide Fri, 12 Apr 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-sql-injection-in-smartfactory-shopfloor-guide/ <no value> [Vulnerability] HTTP NET Remoting ObjRef Leak in .NET Framework public-vulnerability-list/#http-net-remoting-objref-leak-in-net-framework Fri, 22 Mar 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/http-net-remoting-objref-leak-in-net-framework/ <no value> [Blog] Leaking ObjRefs to Exploit HTTP .NET Remoting https://code-white.com/blog/leaking-objrefs-to-exploit-http-dotnet-remoting/ Tue, 27 Feb 2024 00:00:00 +0000 https://code-white.com/blog/leaking-objrefs-to-exploit-http-dotnet-remoting/ How leaking valid `ObjRef`s to target .NET Remoting for Remote Code Execution is not considered a vulnerability – at least according to Microsoft. [Vulnerability] SSRF NetNTLM Leaks in Tableau Server public-vulnerability-list/#ssrf-netntlm-leaks-in-tableau-server Mon, 19 Feb 2024 00:00:00 +0000 https://code-white.com/public-vulnerability-list/ssrf-netntlm-leaks-in-tableau-server/ <no value> [Vulnerability] Authentication Bypass in AI BOX public-vulnerability-list/#authentication-bypass-in-ai-box Tue, 19 Dec 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authentication-bypass-in-ai-box/ <no value> [Vulnerability] PreAuthenticated XXE in CCTV with Observer public-vulnerability-list/#preauthenticated-xxe-in-cctv-with-observer Tue, 19 Dec 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/preauthenticated-xxe-in-cctv-with-observer/ <no value> [Vulnerability] JNDI Injection in Pentaho Business Analytics Server public-vulnerability-list/#jndi-injection-in-pentaho-business-analytics-server Thu, 14 Dec 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/jndi-injection-in-pentaho-business-analytics-server/ <no value> [Vulnerability] Authenticated Remote Code Execution in GridVis public-vulnerability-list/#authenticated-remote-code-execution-in-gridvis Tue, 12 Dec 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-remote-code-execution-in-gridvis/ <no value> [Vulnerability] HardCoded Encryption Password Allows for Authenticated Leak of Cleartext Database Credentials in GridVis public-vulnerability-list/#hardcoded-encryption-password-allows-for-authenticated-leak-of-cleartext-databas Tue, 12 Dec 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/hardcoded-encryption-password-allows-for-authenticated-leak-of-cleartext-databas/ <no value> [Vulnerability] Local Privilege Escalation in VISOR Vision Sensors public-vulnerability-list/#local-privilege-escalation-in-visor-vision-sensors Sun, 10 Dec 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/local-privilege-escalation-in-visor-vision-sensors/ <no value> [Vulnerability] Unauthenticated Arbitrary File Write as Root in PROFINET-INspector NT public-vulnerability-list/#unauthenticated-arbitrary-file-write-as-root-in-profinet-inspector-nt Wed, 29 Nov 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-arbitrary-file-write-as-root-in-profinet-inspector-nt/ <no value> [Vulnerability] Unauthenticated OS Command Injection in PROFINET-INspector NT public-vulnerability-list/#unauthenticated-os-command-injection-in-profinet-inspector-nt Wed, 29 Nov 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-os-command-injection-in-profinet-inspector-nt/ <no value> [Vulnerability] Security Feature Bypass Vulnerability in ASP.NET public-vulnerability-list/#security-feature-bypass-vulnerability-in-asp-net Tue, 14 Nov 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/security-feature-bypass-vulnerability-in-asp-net/ <no value> [Vulnerability] Unauthenticated Serverside Request Forgery in Skype for Business Server public-vulnerability-list/#unauthenticated-serverside-request-forgery-in-skype-for-business-server Tue, 10 Oct 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-serverside-request-forgery-in-skype-for-business-server/ <no value> [Blog] Exploiting ASP.NET TemplateParser — Part II: SharePoint (CVE-2023-33160) https://code-white.com/blog/exploiting-asp.net-templateparser-part-2/ Fri, 29 Sep 2023 00:00:00 +0000 https://code-white.com/blog/exploiting-asp.net-templateparser-part-2/ In Part I, we dug into the internals of the ASP.NET `TemplateParser` and elaborated its capabilities in respect to exploitation. In this part, we will look into whether and how this can also be exploited to gain Remote Code Execution. While this research was originally focussed on the `TemplateParser`, the newly discovered technique was also applicable to SharePoint on-premises and SharePoint Online. So we'll elaborate on how SharePoint protects against the use of malicious code and will present a novel trick that allowed to bypass these security measures (CVE-2023-33160). [Blog] Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813) https://code-white.com/blog/exploiting-asp.net-templateparser-part-1/ Mon, 25 Sep 2023 00:00:00 +0000 https://code-white.com/blog/exploiting-asp.net-templateparser-part-1/ The `TemplateParser` is fundamental in ASP.NET Web Forms. It is used for parsing different ASP.NET source files such as `*.aspx` and for parsing other input from various sources, including user provided data. In this two part series we will take a deep look into `TemplateParser` internals, its capabilities, and how they can be exploited. This knowledge is then applied in the field to demonstrate Remote Code Execution vulnerabilities in Sitecore (CVE-2023-35813) and SharePoint (CVE-2023-33160). [Blog] Blindsiding auditd for Fun and Profit https://code-white.com/blog/2023-08-blindsiding-auditd-for-fun-and-profit/ Thu, 03 Aug 2023 08:40:00 +0200 https://code-white.com/blog/2023-08-blindsiding-auditd-for-fun-and-profit/ [Vulnerability] Local Privilege Escalation in Ivanti Desktop and Server Management public-vulnerability-list/#local-privilege-escalation-in-ivanti-desktop-and-server-management Wed, 26 Jul 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/local-privilege-escalation-in-ivanti-desktop-and-server-management/ <no value> [Vulnerability] Arbitrary Java EL Execution in Workspace public-vulnerability-list/#arbitrary-java-el-execution-in-workspace Sat, 15 Jul 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/arbitrary-java-el-execution-in-workspace/ <no value> [Vulnerability] SPPageparserFilter Bypass in SharePoint public-vulnerability-list/#sppageparserfilter-bypass-in-sharepoint Tue, 11 Jul 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sppageparserfilter-bypass-in-sharepoint/ <no value> [Blog] From Blackbox .NET Remoting to Unauthenticated Remote Code Execution https://code-white.com/blog/2023-07-from-blackbox-dotnet-remoting-to-rce/ Mon, 10 Jul 2023 08:17:48 +0000 https://code-white.com/blog/2023-07-from-blackbox-dotnet-remoting-to-rce/ This is a story on discovering an Unauthenticated Remote Code Execution in a CRM product by the vendor ACT!. What made this story special for us was that we had to take a blackbox approach at the beginning and the system was not exploitable with standard .NET Remoting payloads due to several reasons we'll explain in this blog post. [Vulnerability] Data Source Protection Bypass During XML Deserialization in DevExpress public-vulnerability-list/#data-source-protection-bypass-during-xml-deserialization-in-devexpress Mon, 19 Jun 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/data-source-protection-bypass-during-xml-deserialization-in-devexpress/ <no value> [Vulnerability] Exposed Dangerous Method or Function in Experience Manager, Experience Platform, and Experience Commerce public-vulnerability-list/#exposed-dangerous-method-or-function-in-experience-manager-experience-platform Mon, 19 Jun 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/exposed-dangerous-method-or-function-in-experience-manager-experience-platform/ <no value> [Vulnerability] Insecure Arbitrary TypeConverter Conversion in DevExpress public-vulnerability-list/#insecure-arbitrary-typeconverter-conversion-in-devexpress Mon, 19 Jun 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/insecure-arbitrary-typeconverter-conversion-in-devexpress/ <no value> [Vulnerability] Missing Protection of XtraReport Serialized Data in ASPNET Web Forms in DevExpress public-vulnerability-list/#missing-protection-of-xtrareport-serialized-data-in-aspnet-web-forms-in-devexpre Mon, 19 Jun 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/missing-protection-of-xtrareport-serialized-data-in-aspnet-web-forms-in-devexpre/ <no value> [Vulnerability] ServerSide Request Forgery Via AsyncDownloader in DevExpress public-vulnerability-list/#serverside-request-forgery-via-asyncdownloader-in-devexpress Mon, 19 Jun 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/serverside-request-forgery-via-asyncdownloader-in-devexpress/ <no value> [Vulnerability] Deserialization of Untrusted Data in Pentaho Business Analytics Server public-vulnerability-list/#deserialization-of-untrusted-data-in-pentaho-business-analytics-server Wed, 24 May 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/deserialization-of-untrusted-data-in-pentaho-business-analytics-server/ <no value> [Vulnerability] Unauthenticated Arbitrary File Read as SYSTEM in MCL-Net public-vulnerability-list/#unauthenticated-arbitrary-file-read-as-system-in-mcl-net Fri, 14 Apr 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-arbitrary-file-read-as-system-in-mcl-net/ <no value> [Blog] Java Exploitation Restrictions in Modern JDK Times https://code-white.com/blog/2023-04-java-exploitation-restrictions-in-modern-jdk-times/ Tue, 11 Apr 2023 17:03:00 +0100 https://code-white.com/blog/2023-04-java-exploitation-restrictions-in-modern-jdk-times/ Java deserialization gadgets have a long history in context of vulnerability research and at least go back to the year 2015. One of the most popular tools providing a large set of different gadgets is ysoserial by Chris Frohoff. Recently, we observed increasing concerns from the community why several gadgets do not seem to work anymore with more recent versions of JDKs. In this blog post we try to summarize certain facts to reenable some capabilities which seemed to be broken. But our journey did not begin with deserialization in the first place but rather looking for alternative ways of executing Java code in recent JDK versions. In this blost post, we will focus on OpenJDK and Oracle implementations. Defenders should therefore adjust their search patterns to these alternative code execution patterns accordingly. [Vulnerability] External control of the system or configuration settings in Remote Application Server public-vulnerability-list/#external-control-of-the-system-or-configuration-settings-in-remote-application-s Mon, 10 Apr 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/external-control-of-the-system-or-configuration-settings-in-remote-application-s/ <no value> [Vulnerability] Relative path traversal in Remote Application Server public-vulnerability-list/#relative-path-traversal-in-remote-application-server Mon, 10 Apr 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/relative-path-traversal-in-remote-application-server/ <no value> [Blog] JMX Exploitation Revisited https://code-white.com/blog/2023-03-jmx-exploitation-revisited/ Mon, 20 Mar 2023 12:05:00 +0200 https://code-white.com/blog/2023-03-jmx-exploitation-revisited/ The Java Management Extensions (JMX) are used by many if not all enterprise level applications in Java for managing and monitoring of application settings and metrics. While exploiting an accessible JMX endpoint is well known and there are several free tools available, this blog post will present new insights and a novel exploitation technique that allows for instant Remote Code Execution with no further requirements, such as outgoing connections or the existence of application specific MBeans. [Vulnerability] Multiple Vulnerabilities Unauthenticated in FortiNAC public-vulnerability-list/#multiple-vulnerabilities-unauthenticated-in-fortinac Thu, 02 Mar 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/multiple-vulnerabilities-unauthenticated-in-fortinac/ <no value> [Vulnerability] Hardcoded Administrative Credentials in TG670 DSL gateway router public-vulnerability-list/#hardcoded-administrative-credentials-in-tg670-dsl-gateway-router Mon, 20 Feb 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/hardcoded-administrative-credentials-in-tg670-dsl-gateway-router/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in GoAnywhere MFT public-vulnerability-list/#unauthenticated-remote-code-execution-in-goanywhere-mft Thu, 02 Feb 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-goanywhere-mft/ <no value> [Vulnerability] Multiple Vulnerabilities in Tornado Server public-vulnerability-list/#multiple-vulnerabilities-in-tornado-server Wed, 18 Jan 2023 00:00:00 +0000 https://code-white.com/public-vulnerability-list/multiple-vulnerabilities-in-tornado-server/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in pgAdmin Web (Windows) public-vulnerability-list/#unauthenticated-remote-code-execution-in-pgadmin-web-windows Wed, 23 Nov 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-pgadmin-web-windows/ <no value> [Vulnerability] Unauthenticated XXE in Sophos Mobile public-vulnerability-list/#unauthenticated-xxe-in-sophos-mobile Wed, 09 Nov 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-xxe-in-sophos-mobile/ <no value> [Vulnerability] Unauthorized User Registration in Apache Archiva public-vulnerability-list/#unauthorized-user-registration-in-apache-archiva Mon, 10 Oct 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthorized-user-registration-in-apache-archiva/ <no value> [Vulnerability] LowPriv User Stack Buffer Overflow in 2FA in Kerio Connect public-vulnerability-list/#lowpriv-user-stack-buffer-overflow-in-2fa-in-kerio-connect Fri, 09 Sep 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/lowpriv-user-stack-buffer-overflow-in-2fa-in-kerio-connect/ <no value> [Blog] Attacks on Sysmon Revisited - SysmonEnte https://code-white.com/blog/2022-09-attacks-on-sysmon-revisited-sysmonente/ Tue, 06 Sep 2022 11:02:00 +0200 https://code-white.com/blog/2022-09-attacks-on-sysmon-revisited-sysmonente/ In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed. [Vulnerability] Authentication Bypass in R1Soft Server Backup Manager public-vulnerability-list/#authentication-bypass-in-r1soft-server-backup-manager Tue, 26 Jul 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authentication-bypass-in-r1soft-server-backup-manager/ <no value> [Vulnerability] Authenticated Command Injection in App Platform AP Manager public-vulnerability-list/#authenticated-command-injection-in-app-platform-ap-manager Tue, 12 Jul 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-command-injection-in-app-platform-ap-manager/ <no value> [Vulnerability] Authenticated Command Injection in SEPPmail Appliance public-vulnerability-list/#authenticated-command-injection-in-seppmail-appliance Tue, 12 Jul 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-command-injection-in-seppmail-appliance/ <no value> [Blog] Bypassing .NET Serialization Binders https://code-white.com/blog/2022-06-bypassing-dotnet-serialization-binders/ Tue, 28 Jun 2022 16:00:00 +0200 https://code-white.com/blog/2022-06-bypassing-dotnet-serialization-binders/ [Vulnerability] Authenticated Command Injection in EDR-810 Series public-vulnerability-list/#authenticated-command-injection-in-edr-810-series Tue, 28 Jun 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-command-injection-in-edr-810-series/ <no value> [Vulnerability] Authenticated Command Injection in TN-5916 NAT Router public-vulnerability-list/#authenticated-command-injection-in-tn-5916-nat-router Tue, 28 Jun 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-command-injection-in-tn-5916-nat-router/ <no value> [Vulnerability] Authentication Bypass in TN-5916 NAT Router public-vulnerability-list/#authentication-bypass-in-tn-5916-nat-router Tue, 28 Jun 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authentication-bypass-in-tn-5916-nat-router/ <no value> [Vulnerability] Unauthenticated Remode Code Execution in gRPC Interfaces in SmarterStats public-vulnerability-list/#unauthenticated-remode-code-execution-in-grpc-interfaces-in-smarterstats Thu, 09 Jun 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remode-code-execution-in-grpc-interfaces-in-smarterstats/ <no value> [Vulnerability] Vulnerable RMI Call in Windchill PDMLink public-vulnerability-list/#vulnerable-rmi-call-in-windchill-pdmlink Fri, 03 Jun 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/vulnerable-rmi-call-in-windchill-pdmlink/ <no value> [Vulnerability] RequestDispatcher Local File Inclusion in ZK Framework public-vulnerability-list/#requestdispatcher-local-file-inclusion-in-zk-framework Tue, 10 May 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/requestdispatcher-local-file-inclusion-in-zk-framework/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in Phone Management System public-vulnerability-list/#unauthenticated-remote-code-execution-in-phone-management-system Mon, 14 Feb 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-phone-management-system/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in StoreEver ESL G3 Tape Library public-vulnerability-list/#unauthenticated-remote-code-execution-in-storeever-esl-g3-tape-library Tue, 08 Feb 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-storeever-esl-g3-tape-library/ <no value> [Blog] .NET Remoting Revisited https://code-white.com/blog/2022-01-dotnet-remoting-revisited/ Thu, 27 Jan 2022 15:49:00 +0100 https://code-white.com/blog/2022-01-dotnet-remoting-revisited/ [Vulnerability] Authentication Bypass Unauthenticated Root Password Reset in Citrix ADM public-vulnerability-list/#authentication-bypass-unauthenticated-root-password-reset-in-citrix-adm Thu, 20 Jan 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authentication-bypass-unauthenticated-root-password-reset-in-citrix-adm/ <no value> [Vulnerability] Unauthenticated Service Shutdown in Citrix ADM public-vulnerability-list/#unauthenticated-service-shutdown-in-citrix-adm Thu, 20 Jan 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-service-shutdown-in-citrix-adm/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in ACT! CRM public-vulnerability-list/#unauthenticated-remote-code-execution-in-act-crm Mon, 10 Jan 2022 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-act-crm/ <no value> [Vulnerability] Deserialization Protection Bypass in Exchange 2013/2016/2019 public-vulnerability-list/#deserialization-protection-bypass-in-exchange-2013-2016-2019 Wed, 15 Dec 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/deserialization-protection-bypass-in-exchange-2013-2016-2019/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in ADMIRA/AREMA public-vulnerability-list/#unauthenticated-remote-code-execution-in-admira-arema Thu, 04 Nov 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-admira-arema/ <no value> [Vulnerability] Unauthenticated Remote Code Execution in TPT public-vulnerability-list/#unauthenticated-remote-code-execution-in-tpt Mon, 25 Oct 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-tpt/ <no value> [Vulnerability] Authenticated XXE in TIBCO JasperReports Server public-vulnerability-list/#authenticated-xxe-in-tibco-jasperreports-server Thu, 21 Oct 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-xxe-in-tibco-jasperreports-server/ <no value> [Vulnerability] Unauthenticated RCE via Unsafe Cookie Deserialization in HelpSpot public-vulnerability-list/#unauthenticated-rce-via-unsafe-cookie-deserialization-in-helpspot Fri, 01 Oct 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-rce-via-unsafe-cookie-deserialization-in-helpspot/ <no value> [Blog] RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through https://code-white.com/blog/2021-09-citrix-sharefile-rce-cve-2021-22941/ Tue, 21 Sep 2021 10:04:00 +0200 https://code-white.com/blog/2021-09-citrix-sharefile-rce-cve-2021-22941/ [Vulnerability] UnAuthenticated Remote Code Execution in Jedox public-vulnerability-list/#unauthenticated-remote-code-execution-in-jedox Tue, 21 Sep 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-in-jedox/ <no value> [Vulnerability] NET Deserialization in Cerberus DSM, Desigo CC, Desigo CC Compact public-vulnerability-list/#net-deserialization-in-cerberus-dsm-desigo-cc-desigo-cc-compact Tue, 14 Sep 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-cerberus-dsm-desigo-cc-desigo-cc-compact/ <no value> [Vulnerability] Arbitrary File Reading via Hardcoded Crypto Key in Storefront public-vulnerability-list/#arbitrary-file-reading-via-hardcoded-crypto-key-in-storefront Tue, 03 Aug 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/arbitrary-file-reading-via-hardcoded-crypto-key-in-storefront/ <no value> [Vulnerability] RCE via Arbitrary Class Execution in Lobster AdminConsole public-vulnerability-list/#rce-via-arbitrary-class-execution-in-lobster-adminconsole Wed, 28 Jul 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/rce-via-arbitrary-class-execution-in-lobster-adminconsole/ <no value> [Vulnerability] Local Privilege Escalation to SYSTEM in Aternity Agent public-vulnerability-list/#local-privilege-escalation-to-system-in-aternity-agent Fri, 18 Jun 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/local-privilege-escalation-to-system-in-aternity-agent/ <no value> [Blog] About the Unsuccessful Quest for a Deserialization Gadget (or: How I found CVE-2021-21481) https://code-white.com/blog/2021-06-about-unsuccessful-quest-for/ Fri, 11 Jun 2021 12:05:00 +0200 https://code-white.com/blog/2021-06-about-unsuccessful-quest-for/ [Vulnerability] Path Traversal in ShareFile StorageZone Controller public-vulnerability-list/#path-traversal-in-sharefile-storagezone-controller Fri, 30 Apr 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/path-traversal-in-sharefile-storagezone-controller/ <no value> [Vulnerability] NET Deserialization via NET Remoting in Backup & Replication public-vulnerability-list/#net-deserialization-via-net-remoting-in-backup-replication Fri, 15 Jan 2021 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-via-net-remoting-in-backup-replication/ <no value> [Vulnerability] Several Unauthenticated Remote Code Executions File Reads and Writes in Security Manager public-vulnerability-list/#several-unauthenticated-remote-code-executions-file-reads-and-writes-in-security Tue, 08 Dec 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/several-unauthenticated-remote-code-executions-file-reads-and-writes-in-security/ <no value> [Vulnerability] Various vulnerabilities file read file write SQL injection XSL transformation DataSet deserialization in Protean CMS public-vulnerability-list/#various-vulnerabilities-file-read-file-write-sql-injection-xsl-transformation-da Wed, 09 Sep 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/various-vulnerabilities-file-read-file-write-sql-injection-xsl-transformation-da/ <no value> [Vulnerability] LFI leads to RCE in WebConfig public-vulnerability-list/#lfi-leads-to-rce-in-webconfig Wed, 02 Sep 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/lfi-leads-to-rce-in-webconfig/ <no value> [Blog] Sophos XG - A Tale of the Unfortunate Re-engineering of an N-Day and the Lucky Find of a 0-Day https://code-white.com/blog/2020-07-sophos-xg-tale-of-unfortunate-re/ Mon, 13 Jul 2020 16:46:00 +0200 https://code-white.com/blog/2020-07-sophos-xg-tale-of-unfortunate-re/ [Vulnerability] SQL Injection in Firewall XG public-vulnerability-list/#sql-injection-in-firewall-xg Mon, 13 Jul 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sql-injection-in-firewall-xg/ <no value> [Vulnerability] Java Deserialization in WebLogic Server public-vulnerability-list/#java-deserialization-in-weblogic-server Mon, 11 May 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-weblogic-server/ <no value> [Vulnerability] Arbitrary File Read in Spring Web MVC public-vulnerability-list/#arbitrary-file-read-in-spring-web-mvc Wed, 29 Apr 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/arbitrary-file-read-in-spring-web-mvc/ <no value> [Vulnerability] Unauthenticated Remote Code Execution via NET Remoting in SmarterStats public-vulnerability-list/#unauthenticated-remote-code-execution-via-net-remoting-in-smarterstats Fri, 17 Apr 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-via-net-remoting-in-smarterstats/ <no value> [Vulnerability] Unauthenticated access to encrypted administration credentials in Dell VxRail public-vulnerability-list/#unauthenticated-access-to-encrypted-administration-credentials-in-dell-vxrail Thu, 16 Apr 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-access-to-encrypted-administration-credentials-in-dell-vxrail/ <no value> [Vulnerability] Authenticated Remote Code Execution via unsecure Java deserialization in OpenNMS public-vulnerability-list/#authenticated-remote-code-execution-via-unsecure-java-deserialization-in-opennms Wed, 15 Apr 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-remote-code-execution-via-unsecure-java-deserialization-in-opennms/ <no value> [Vulnerability] Unauthenticated change of system configuration via unprotected Java servlets in ManageEngine ADManager Plus, ManageEngine Cloud Security Plus, ManageEngine Log360, ManageEngine ADAudit Plus, ManageEngine DataSecurity Plus, ManageEngine O365 Manager Plus, ManageEngine RecoveryManager Plus, ManageEngine EventLog Analyzer public-vulnerability-list/#unauthenticated-change-of-system-configuration-via-unprotected-java-servlets-in Wed, 15 Apr 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-change-of-system-configuration-via-unprotected-java-servlets-in/ <no value> [Vulnerability] Unauthenticated Remote Code Execution via unsecure Java deserialization in HPE Insight Systems Manager public-vulnerability-list/#unauthenticated-remote-code-execution-via-unsecure-java-deserialization-in-hpe-i Wed, 08 Apr 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-via-unsecure-java-deserialization-in-hpe-i/ <no value> [Vulnerability] 622 631 in Avalanche Data Repository Service public-vulnerability-list/#622-631-in-avalanche-data-repository-service Mon, 06 Apr 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/622-631-in-avalanche-data-repository-service/ <no value> [Blog] Liferay Portal JSON Web Service RCE Vulnerabilities https://code-white.com/blog/2020-03-liferay-portal-json-vulns/ Fri, 20 Mar 2020 13:31:00 +0100 https://code-white.com/blog/2020-03-liferay-portal-json-vulns/ [Vulnerability] Java Deserialization in Portal public-vulnerability-list/#java-deserialization-in-portal Fri, 20 Mar 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-portal/ <no value> [Vulnerability] Arbitrary File Upload in Telerik UI for Silverlight public-vulnerability-list/#arbitrary-file-upload-in-telerik-ui-for-silverlight Tue, 17 Mar 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/arbitrary-file-upload-in-telerik-ui-for-silverlight/ <no value> [Vulnerability] Missing Authorization Check in SAP NetWeaver AS JAVA MigrationService in Netweaver public-vulnerability-list/#missing-authorization-check-in-sap-netweaver-as-java-migrationservice-in-netweav Mon, 09 Mar 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/missing-authorization-check-in-sap-netweaver-as-java-migrationservice-in-netweav/ <no value> [Vulnerability] in SmarterMail public-vulnerability-list/#in-smartermail Thu, 27 Feb 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/in-smartermail/ <no value> [Vulnerability] Java Deserialization in FortiSIEM public-vulnerability-list/#java-deserialization-in-fortisiem Mon, 10 Feb 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-fortisiem/ <no value> [Blog] CVE-2019-19470: Rumble in the Pipe https://code-white.com/blog/2020-01-cve-2019-19470-rumble-in-pipe/ Fri, 17 Jan 2020 10:18:00 +0100 https://code-white.com/blog/2020-01-cve-2019-19470-rumble-in-pipe/ [Vulnerability] Authentication Bypass Path Traversal in ASES public-vulnerability-list/#authentication-bypass-path-traversal-in-ases Fri, 17 Jan 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authentication-bypass-path-traversal-in-ases/ <no value> [Vulnerability] Path Traversal in Telerik MVC public-vulnerability-list/#path-traversal-in-telerik-mvc Wed, 08 Jan 2020 00:00:00 +0000 https://code-white.com/public-vulnerability-list/path-traversal-in-telerik-mvc/ <no value> [Vulnerability] Privilege escalation via unsecure NET deserialization and Process Spoofing in TinyWall public-vulnerability-list/#privilege-escalation-via-unsecure-net-deserialization-and-process-spoofing-in-ti Wed, 27 Nov 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/privilege-escalation-via-unsecure-net-deserialization-and-process-spoofing-in-ti/ <no value> [Vulnerability] Java Deserialization in 300 People public-vulnerability-list/#java-deserialization-in-300-people Thu, 21 Nov 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-300-people/ <no value> [Vulnerability] Authenticated Remote Code Execution via unsecure NET deserialization in C1 CMS public-vulnerability-list/#authenticated-remote-code-execution-via-unsecure-net-deserialization-in-c1-cms Fri, 18 Oct 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-remote-code-execution-via-unsecure-net-deserialization-in-c1-cms/ <no value> [Vulnerability] Unauthenticated SQLInjection via unprotected Java servlet in ManageEngine OpManager public-vulnerability-list/#unauthenticated-sqlinjection-via-unprotected-java-servlet-in-manageengine-opmana Wed, 09 Oct 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-sqlinjection-via-unprotected-java-servlet-in-manageengine-opmana/ <no value> [Vulnerability] Mitigation Bypass in Telerik UI for Ajax ASP.NET public-vulnerability-list/#mitigation-bypass-in-telerik-ui-for-ajax-asp-net Tue, 01 Oct 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/mitigation-bypass-in-telerik-ui-for-ajax-asp-net/ <no value> [Vulnerability] NET Deserialization in myLittleAdmin public-vulnerability-list/#net-deserialization-in-mylittleadmin Tue, 27 Aug 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-mylittleadmin/ <no value> [Vulnerability] Path Traversal Unauthenticated Socks5 Proxy in MailEnable public-vulnerability-list/#path-traversal-unauthenticated-socks5-proxy-in-mailenable Mon, 26 Aug 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/path-traversal-unauthenticated-socks5-proxy-in-mailenable/ <no value> [Blog] Exploiting H2 Database with native libraries and JNI https://code-white.com/blog/2019-08-exploit-h2-database-native-libraries-jni/ Thu, 01 Aug 2019 14:54:00 +0200 https://code-white.com/blog/2019-08-exploit-h2-database-native-libraries-jni/ [Vulnerability] Java Deserialization in cpanel-dovecot-solr public-vulnerability-list/#java-deserialization-in-cpanel-dovecot-solr Thu, 25 Jul 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-cpanel-dovecot-solr/ <no value> [Vulnerability] Authenticated Remote Code Execution via unsecure Java deserialization in FTAPI public-vulnerability-list/#authenticated-remote-code-execution-via-unsecure-java-deserialization-in-ftapi Mon, 22 Jul 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-remote-code-execution-via-unsecure-java-deserialization-in-ftapi/ <no value> [Blog] Heap-based AMSI bypass for MS Excel VBA and others https://code-white.com/blog/2019-07-heap-based-amsi-bypass-in-vba/ Fri, 19 Jul 2019 14:03:00 +0200 https://code-white.com/blog/2019-07-heap-based-amsi-bypass-in-vba/ [Vulnerability] NET Deserialization in public-vulnerability-list/#net-deserialization-in Tue, 04 Jun 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in/ <no value> [Vulnerability] Java Deserialization in Secure Global Desktop public-vulnerability-list/#java-deserialization-in-secure-global-desktop Fri, 17 May 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-secure-global-desktop/ <no value> [Vulnerability] Unauthenticated Remote Code Execution via unprotected RMIRegistry in IBM ServRAID public-vulnerability-list/#unauthenticated-remote-code-execution-via-unprotected-rmiregistry-in-ibm-servrai Wed, 27 Mar 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/unauthenticated-remote-code-execution-via-unprotected-rmiregistry-in-ibm-servrai/ <no value> [Vulnerability] XXE in SyncML XXE in Keyoti RapidSpell in SmarterMail public-vulnerability-list/#xxe-in-syncml-xxe-in-keyoti-rapidspell-in-smartermail Tue, 12 Feb 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/xxe-in-syncml-xxe-in-keyoti-rapidspell-in-smartermail/ <no value> [Blog] Telerik Revisited https://code-white.com/blog/2019-02-telerik-revisited/ Thu, 07 Feb 2019 11:04:00 +0100 https://code-white.com/blog/2019-02-telerik-revisited/ [Vulnerability] NET Deserialization in CribMaster public-vulnerability-list/#net-deserialization-in-cribmaster Thu, 07 Feb 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-cribmaster/ <no value> [Vulnerability] NET Deserialization in Telerik UI for Ajax ASP.NET public-vulnerability-list/#net-deserialization-in-telerik-ui-for-ajax-asp-net Thu, 07 Feb 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-telerik-ui-for-ajax-asp-net/ <no value> [Vulnerability] NET Deserialization in DevExpress public-vulnerability-list/#net-deserialization-in-devexpress Mon, 14 Jan 2019 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-devexpress/ <no value> [Vulnerability] Authenticated file system data exfiltration via SOAP webservice in ILIAS public-vulnerability-list/#authenticated-file-system-data-exfiltration-via-soap-webservice-in-ilias Tue, 04 Dec 2018 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authenticated-file-system-data-exfiltration-via-soap-webservice-in-ilias/ <no value> [Vulnerability] NET Deserialization in Managed Workplace RMM public-vulnerability-list/#net-deserialization-in-managed-workplace-rmm Tue, 13 Nov 2018 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-managed-workplace-rmm/ <no value> [Blog] LethalHTA - A new lateral movement technique using DCOM and HTA https://code-white.com/blog/2018-07-lethalhta/ Fri, 06 Jul 2018 14:08:00 +0200 https://code-white.com/blog/2018-07-lethalhta/ [Blog] Marshalling to SYSTEM - An analysis of CVE-2018-0824 https://code-white.com/blog/2018-06-cve-2018-0624/ Fri, 15 Jun 2018 15:19:00 +0200 https://code-white.com/blog/2018-06-cve-2018-0624/ [Blog] Poor RichFaces https://code-white.com/blog/2018-05-poor-richfaces/ Wed, 30 May 2018 15:00:00 +0200 https://code-white.com/blog/2018-05-poor-richfaces/ [Vulnerability] EL Injection in RichFaces public-vulnerability-list/#el-injection-in-richfaces Wed, 30 May 2018 00:00:00 +0000 https://code-white.com/public-vulnerability-list/el-injection-in-richfaces/ <no value> [Vulnerability] EL Injection in RichFaces public-vulnerability-list/#el-injection-in-richfaces Wed, 30 May 2018 00:00:00 +0000 https://code-white.com/public-vulnerability-list/el-injection-in-richfaces/ <no value> [Vulnerability] NET Deserialization in Genuine Channels public-vulnerability-list/#net-deserialization-in-genuine-channels Mon, 23 Apr 2018 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-genuine-channels/ <no value> [Vulnerability] Java Deserialization in GWT public-vulnerability-list/#java-deserialization-in-gwt Fri, 13 Apr 2018 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-gwt/ <no value> [Blog] Exploiting Adobe ColdFusion before CVE-2017-3066 https://code-white.com/blog/2018-03-exploiting-adobe-coldfusion/ Tue, 13 Mar 2018 15:41:00 +0100 https://code-white.com/blog/2018-03-exploiting-adobe-coldfusion/ [Vulnerability] NET Deserialization in public-vulnerability-list/#net-deserialization-in Thu, 22 Feb 2018 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in/ <no value> [Blog] Handcrafted Gadgets https://code-white.com/blog/2018-01-handcrafted-gadgets/ Thu, 18 Jan 2018 16:07:00 +0100 https://code-white.com/blog/2018-01-handcrafted-gadgets/ [Vulnerability] El Injection in public-vulnerability-list/#el-injection-in Thu, 17 Aug 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/el-injection-in/ <no value> [Blog] SAP Customers: Make sure your SAPJVM is up-to-date! https://code-white.com/blog/2017-05-sap-customers-make-sure-your-sapjvm-is/ Wed, 17 May 2017 16:56:00 +0200 https://code-white.com/blog/2017-05-sap-customers-make-sure-your-sapjvm-is/ [Vulnerability] Java Deserialization in P4 public-vulnerability-list/#java-deserialization-in-p4 Wed, 17 May 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-p4/ <no value> [Blog] AMF – Another Malicious Format https://code-white.com/blog/2017-04-amf/ Tue, 04 Apr 2017 16:01:00 +0200 https://code-white.com/blog/2017-04-amf/ [Vulnerability] Java Deserialization in public-vulnerability-list/#java-deserialization-in Tue, 04 Apr 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in/ <no value> [Vulnerability] Java Deserialization in Jira public-vulnerability-list/#java-deserialization-in-jira Tue, 04 Apr 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-jira/ <no value> [Vulnerability] Java Deserialization in Spring Flex public-vulnerability-list/#java-deserialization-in-spring-flex Tue, 04 Apr 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-spring-flex/ <no value> [Vulnerability] Java Deserialization JavaBeans Setter in GraniteDS public-vulnerability-list/#java-deserialization-javabeans-setter-in-graniteds Tue, 04 Apr 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-javabeans-setter-in-graniteds/ <no value> [Vulnerability] Java Deserialization JavaBeans Setter XXE in Flamingo amf-serializer public-vulnerability-list/#java-deserialization-javabeans-setter-xxe-in-flamingo-amf-serializer Tue, 04 Apr 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-javabeans-setter-xxe-in-flamingo-amf-serializer/ <no value> [Vulnerability] Java Deserialization JavaBeans Setter XXE in Flex BlazeDS public-vulnerability-list/#java-deserialization-javabeans-setter-xxe-in-flex-blazeds Tue, 04 Apr 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-javabeans-setter-xxe-in-flex-blazeds/ <no value> [Vulnerability] Java Deserialization XXE in WebORB for Java public-vulnerability-list/#java-deserialization-xxe-in-weborb-for-java Tue, 04 Apr 2017 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-xxe-in-weborb-for-java/ <no value> [Vulnerability] Arbitrary File Upload in ezPublish public-vulnerability-list/#arbitrary-file-upload-in-ezpublish Fri, 25 Nov 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/arbitrary-file-upload-in-ezpublish/ <no value> [Vulnerability] SQL Injection in ezPublish public-vulnerability-list/#sql-injection-in-ezpublish Wed, 05 Oct 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sql-injection-in-ezpublish/ <no value> [Vulnerability] Java Deserialization in CrashPlan PROe public-vulnerability-list/#java-deserialization-in-crashplan-proe Fri, 16 Sep 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-crashplan-proe/ <no value> [Vulnerability] in Service Manager public-vulnerability-list/#in-service-manager Wed, 25 May 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/in-service-manager/ <no value> [Blog] Return of the Rhino: An old gadget revisited https://code-white.com/blog/2016-05-return-of-rhino-old-gadget-revisited/ Wed, 04 May 2016 21:06:00 +0200 https://code-white.com/blog/2016-05-return-of-rhino-old-gadget-revisited/ [Blog] Infiltrate 2016 Slidedeck: Java Deserialization Vulnerabilities https://code-white.com/blog/2016-04-infiltrate16-slidedeck-java-deserialization/ Tue, 12 Apr 2016 16:11:00 +0200 https://code-white.com/blog/2016-04-infiltrate16-slidedeck-java-deserialization/ [Vulnerability] SQL Injection Path Traversal JSP File Inclusion in Edge Server public-vulnerability-list/#sql-injection-path-traversal-jsp-file-inclusion-in-edge-server Thu, 24 Mar 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sql-injection-path-traversal-jsp-file-inclusion-in-edge-server/ <no value> [Vulnerability] Java Deserialization in Hyperion public-vulnerability-list/#java-deserialization-in-hyperion Thu, 17 Mar 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-hyperion/ <no value> [Blog] Compromised by Endpoint Protection: Legacy Edition https://code-white.com/blog/2016-02-symantec-endpoint-protection-legacy-edition/ Tue, 23 Feb 2016 14:50:00 +0100 https://code-white.com/blog/2016-02-symantec-endpoint-protection-legacy-edition/ [Vulnerability] in Endpoint Protection public-vulnerability-list/#in-endpoint-protection Mon, 22 Feb 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/in-endpoint-protection/ <no value> [Blog] Java and Command Line Injections in Windows https://code-white.com/blog/2016-02-java-and-command-line-injections-in-windows/ Thu, 04 Feb 2016 17:03:00 +0100 https://code-white.com/blog/2016-02-java-and-command-line-injections-in-windows/ [Vulnerability] Arbitrary File UploadDownload in Edge Server public-vulnerability-list/#arbitrary-file-uploaddownload-in-edge-server Tue, 05 Jan 2016 00:00:00 +0000 https://code-white.com/public-vulnerability-list/arbitrary-file-uploaddownload-in-edge-server/ <no value> [Vulnerability] Java Deserialization XXE in Service Manager public-vulnerability-list/#java-deserialization-xxe-in-service-manager Fri, 18 Dec 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-xxe-in-service-manager/ <no value> [Vulnerability] Java Deserialization in Weblogic JMS Client public-vulnerability-list/#java-deserialization-in-weblogic-jms-client Wed, 09 Dec 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-weblogic-jms-client/ <no value> [Vulnerability] Java Deserialization in WebSphere MQ JMS Client public-vulnerability-list/#java-deserialization-in-websphere-mq-jms-client Tue, 08 Dec 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-websphere-mq-jms-client/ <no value> [Vulnerability] Command Injection in Endpoint Protection Manager public-vulnerability-list/#command-injection-in-endpoint-protection-manager Mon, 16 Nov 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/command-injection-in-endpoint-protection-manager/ <no value> [Vulnerability] Java Deserialization in Endpoint Protection Manager public-vulnerability-list/#java-deserialization-in-endpoint-protection-manager Mon, 16 Nov 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-endpoint-protection-manager/ <no value> [Vulnerability] Java Deserialization in Active MQ public-vulnerability-list/#java-deserialization-in-active-mq Tue, 03 Nov 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-active-mq/ <no value> [Vulnerability] in Community public-vulnerability-list/#in-community Fri, 02 Oct 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/in-community/ <no value> [Vulnerability] Java Deserialization Command Injection in Edge Server public-vulnerability-list/#java-deserialization-command-injection-in-edge-server Fri, 04 Sep 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-command-injection-in-edge-server/ <no value> [Blog] CVE-2015-3269: Apache Flex BlazeDS XXE Vulnerabilty https://code-white.com/blog/2015-08-cve-2015-3269-apache-flex-blazeds-xxe/ Mon, 24 Aug 2015 13:23:00 +0200 https://code-white.com/blog/2015-08-cve-2015-3269-apache-flex-blazeds-xxe/ [Vulnerability] in Flex BlazeDS public-vulnerability-list/#in-flex-blazeds Mon, 24 Aug 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/in-flex-blazeds/ <no value> [Vulnerability] Java Deserialization in Bamboo public-vulnerability-list/#java-deserialization-in-bamboo Fri, 21 Aug 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-bamboo/ <no value> [Blog] Compromised by Endpoint Protection https://code-white.com/blog/2015-07-symantec-endpoint-protection/ Fri, 31 Jul 2015 08:23:00 +0200 https://code-white.com/blog/2015-07-symantec-endpoint-protection/ [Vulnerability] Authentication Bypass Arbitrary File WriteRead Privilege Escalation Path Traversal SQL Injection Binary Planting in Endpoint Protection public-vulnerability-list/#authentication-bypass-arbitrary-file-writeread-privilege-escalation-path-travers Fri, 31 Jul 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/authentication-bypass-arbitrary-file-writeread-privilege-escalation-path-travers/ <no value> [Vulnerability] SQL Injection in webEdition public-vulnerability-list/#sql-injection-in-webedition Wed, 22 Jul 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sql-injection-in-webedition/ <no value> [Vulnerability] SQL Injection in WebsiteBaker public-vulnerability-list/#sql-injection-in-websitebaker Tue, 21 Jul 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sql-injection-in-websitebaker/ <no value> [Vulnerability] Java Deserialization in WebLogic Server public-vulnerability-list/#java-deserialization-in-weblogic-server Mon, 15 Jun 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-weblogic-server/ <no value> [Blog] Reading/Writing files with MSSQL's OPENROWSET https://code-white.com/blog/2015-06-reading-and-writing-files-with-mssql-openrowset/ Tue, 09 Jun 2015 15:19:00 +0200 https://code-white.com/blog/2015-06-reading-and-writing-files-with-mssql-openrowset/ [Blog] CVE-2015-2079: Arbitrary Command Execution in Usermin https://code-white.com/blog/2015-05-cve-2015-2079-rce-usermin/ Wed, 20 May 2015 14:56:00 +0200 https://code-white.com/blog/2015-05-cve-2015-2079-rce-usermin/ [Vulnerability] Command Execution in Usermin public-vulnerability-list/#command-execution-in-usermin Wed, 20 May 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/command-execution-in-usermin/ <no value> [Blog] CVE-2015-0935: PHP Object Injection in Bomgar Remote Support Portal https://code-white.com/blog/2015-05-cve-2015-0935-bomgar-remote-support-portal/ Fri, 08 May 2015 20:48:00 +0200 https://code-white.com/blog/2015-05-cve-2015-0935-bomgar-remote-support-portal/ [Blog] $@|sh – Or: Getting a shell environment from Runtime.exec https://code-white.com/blog/2015-03-sh-or-getting-shell-environment-from/ Mon, 09 Mar 2015 09:55:00 +0100 https://code-white.com/blog/2015-03-sh-or-getting-shell-environment-from/ [Blog] Exploiting the hidden Saxon XSLT Parser in Ektron CMS https://code-white.com/blog/2015-03-exploiting-hidden-saxon-xslt-parser-in/ Mon, 02 Mar 2015 14:54:00 +0100 https://code-white.com/blog/2015-03-exploiting-hidden-saxon-xslt-parser-in/ [Blog] How I could (i)pass your client security https://code-white.com/blog/2015-02-how-i-could-ipass-your-client-security/ Wed, 25 Feb 2015 16:55:00 +0100 https://code-white.com/blog/2015-02-how-i-could-ipass-your-client-security/ [Vulnerability] Privilege Escalation via named pipe in iPass Open Mobile public-vulnerability-list/#privilege-escalation-via-named-pipe-in-ipass-open-mobile Wed, 21 Jan 2015 00:00:00 +0000 https://code-white.com/public-vulnerability-list/privilege-escalation-via-named-pipe-in-ipass-open-mobile/ <no value> [Vulnerability] in Jira public-vulnerability-list/#in-jira Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/in-jira/ <no value> [Vulnerability] Binary Planting in Management Server Client public-vulnerability-list/#binary-planting-in-management-server-client Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/binary-planting-in-management-server-client/ <no value> [Vulnerability] Java Deserialization in ActiveMQ Artemis JMS Client public-vulnerability-list/#java-deserialization-in-activemq-artemis-jms-client Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-activemq-artemis-jms-client/ <no value> [Vulnerability] Java Deserialization in Qpid Client/JMS Client public-vulnerability-list/#java-deserialization-in-qpid-client-jms-client Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-qpid-client-jms-client/ <no value> [Vulnerability] Java Deserialization in Spring AMQP public-vulnerability-list/#java-deserialization-in-spring-amqp Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-spring-amqp/ <no value> [Vulnerability] Java Deserialization in Weblogic Server public-vulnerability-list/#java-deserialization-in-weblogic-server Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-weblogic-server/ <no value> [Vulnerability] Java Deserialization in WebLogic Server public-vulnerability-list/#java-deserialization-in-weblogic-server Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/java-deserialization-in-weblogic-server/ <no value> [Vulnerability] Named Pipe Process Call Arbitrary in Management Server public-vulnerability-list/#named-pipe-process-call-arbitrary-in-management-server Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/named-pipe-process-call-arbitrary-in-management-server/ <no value> [Vulnerability] NET Deserialization in Skype for Business public-vulnerability-list/#net-deserialization-in-skype-for-business Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/net-deserialization-in-skype-for-business/ <no value> [Vulnerability] Path Traversal in Management Server public-vulnerability-list/#path-traversal-in-management-server Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/path-traversal-in-management-server/ <no value> [Vulnerability] Path TraversalBinary Planting on Deployed Agent in Management Server public-vulnerability-list/#path-traversalbinary-planting-on-deployed-agent-in-management-server Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/path-traversalbinary-planting-on-deployed-agent-in-management-server/ <no value> [Vulnerability] PHP Deserialization in Remote Support Portal public-vulnerability-list/#php-deserialization-in-remote-support-portal Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/php-deserialization-in-remote-support-portal/ <no value> [Vulnerability] SQL Injection in Management Server public-vulnerability-list/#sql-injection-in-management-server Mon, 01 Jan 0001 00:00:00 +0000 https://code-white.com/public-vulnerability-list/sql-injection-in-management-server/ <no value>