home.social

#commandinjection — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #commandinjection, aggregated by home.social.

  1. GitHub Flaw Exposes Remote Code Execution to Authenticated Users

    A single git push command was all it took to exploit a flaw in GitHub's internal protocol, allowing authenticated users to execute code on backend infrastructure. This shocking vulnerability, tracked as CVE-2026-3854, highlights the potential for devastating remote code execution attacks.

    osintsights.com/github-flaw-ex

    #RemoteCodeExecution #Github #Cve20263854 #CommandInjection #SupplyChain

  2. GitHub Flaw Exposes Remote Code Execution to Authenticated Users

    A single git push command was all it took to exploit a flaw in GitHub's internal protocol, allowing authenticated users to execute code on backend infrastructure. This shocking vulnerability, tracked as CVE-2026-3854, highlights the potential for devastating remote code execution attacks.

    osintsights.com/github-flaw-ex

    #RemoteCodeExecution #Github #Cve20263854 #CommandInjection #SupplyChain

  3. SGLang Flaw Enables Remote Code Execution via Malicious Model Files

    A single malicious file can become a powerful gateway for attackers to run arbitrary commands on vulnerable machines - and a newly disclosed flaw in SGLang, CVE-2026-5760, reveals just how easily this can happen through specially crafted GGUF model files. This highly severe vulnerability, scoring 9.8 out of 10.0, enables remote code…

    osintsights.com/sglang-flaw-en

    #RemoteCodeExecution #Cve20265760 #CommandInjection #Gguf #Sglang

  4. SGLang Flaw Enables Remote Code Execution via Malicious Model Files

    A single malicious file can become a powerful gateway for attackers to run arbitrary commands on vulnerable machines - and a newly disclosed flaw in SGLang, CVE-2026-5760, reveals just how easily this can happen through specially crafted GGUF model files. This highly severe vulnerability, scoring 9.8 out of 10.0, enables remote code…

    osintsights.com/sglang-flaw-en

    #RemoteCodeExecution #Cve20265760 #CommandInjection #Gguf #Sglang

  5. Kolejny problem Fortineta – podatne FortiSIEM pod ostrzałem

    Mamy wrażenie, że nie tylko nas zaczynają nużyć problemy produktów bezpieczeństwa, zwłaszcza od kilku firm… . Tym razem legendarny badacz SinSinology prezentuje krytyczną podatność (9.8 w skali CVSS w biuletynie bezpieczeństwa producenta) w produkcie dedykowanym dużym organizacjom – FortiSIEM. TLDR: Sprawa nie jest błaha, ponieważ jak informuje Fortinet luka ta...

    #WBiegu #CommandInjection #Fortinet #Podatność #Rce #Siem #Websec

    sekurak.pl/kolejny-problem-for

  6. PHP Composer Flaws Expose Code Execution Risk, Prompting Patches

    Critical flaws in PHP Composer, a popular package manager, leave countless websites vulnerable to code execution attacks - but fortunately, patches have been released to swiftly mitigate this risk. If exploited, these high-severity vulnerabilities could allow hackers to execute arbitrary commands, putting entire…

    osintsights.com/php-composer-f

    #PhpComposer #CodeExecution #PackageManager #CommandInjection #VulnerabilityManagement

  7. Zdalne wykonanie kodu bez uwierzytelnienia na Centosie – panel CWP

    CentOS Web Panel to darmowe rozwiązanie dostępne na systemach z rodziny CentOS (lub korzystających z RPM), składające się właściwie z dwóch elementów. Oferuje interfejs administratorski do zarządzania serwerem, konfiguracji usług takich jak serwery WWW, poczty e-mail czy DNS. Oprócz tego, na innym porcie udostępniany jest drugi panel dla użytkowników końcowych,...

    #WBiegu #Authbypass #Centos #CommandInjection #Cwp #Rce #Websec

    sekurak.pl/zdalne-wykonanie-ko

  8. CVE-2024-3400 PAN-OS: OS Command Injection #Vulnerability in #GlobalProtect Gateway

    A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

    This issue will be fixed in hotfix releases of PAN-OS 10.2.9-h1 (ETA: By 4/14), PAN-OS 11.0.4-h1 (ETA: By 4/14), and PAN-OS 11.1.2-h3 (ETA: By 4/14), and in all later PAN-OS versions.

    ref: security.paloaltonetworks.com/ #paloaltonetworks #commandinjection #vulnerability #infosec #cybersecurity #cve20243400

  9. ~Chińscy hackerzy przeniknęli do komputerów Departamentu Skarbu USA. Włamali się do dostawcy usługi zdalnego dostępu.

    Najpierw zhackowali jednego z dostawców – tj. firmę BeyondTrust (zapewniającą w szczególności usługi związane ze zdalnym dostępem). A dokładniej – zhackowali usługę zapewniającą zdalny dostęp… i taki dostęp uzyskali na komputerach m.in. jednego z klientów firmy – tj. Departamentu Skarbu USA. Następnie hackerzy wykradli stamtąd „pewne dane”. W trakcie dochodzenia...

    #WBiegu #Apt #Chiny #CommandInjection #Hack #Usa #ZdalnyDostęp

    sekurak.pl/chinscy-hackerzy-pr

  10. Cisco IMC Command Injection Vulnerability Alert

    Date: April 17, 2024
    CVE: CVE-2024-20356
    Vulnerability Type: Command Injection
    CWE: [[CWE-78]]
    Sources: Cisco Security Advisory

    Issue Summary

    A critical vulnerability has been identified in the Cisco Integrated Management Controller (IMC) web-based management interface. This flaw allows authenticated, remote attackers with Administrator-level privileges to perform command injection attacks, potentially gaining root access to the affected systems. Cisco has acknowledged the vulnerability and provided software updates to mitigate the issue.

    Technical Key findings

    The vulnerability results from inadequate input validation of command strings by the web-based management interface. Attackers can exploit this by sending specially crafted commands to the interface, which are then executed with elevated privileges.

    Vulnerable products

    • 5000 Series Enterprise Network Compute Systems (ENCS)
    • Catalyst 8300 Series Edge uCPE
    • UCS C-Series M5, M6, and M7 Rack Servers (standalone mode)
    • UCS E-Series Servers
    • UCS S-Series Storage Servers (standalone mode)

    Impact assessment

    Successful exploitation allows attackers to elevate privileges to root, leading to full system control. This can result in unauthorized access, data leakage, and potential interruption of operations.

    Patches or workaround

    No workarounds are available. Cisco recommends updating to the latest firmware versions provided in their security advisory to address this vulnerability.

    Tags

    #Cisco #CVE-2024-20356 #CommandInjection #CIMC #ITSecurity #PatchManagement

  11. Critical Command Injection Vulnerability in Palo Alto Networks PAN-OS

    Date: 2024-04-12
    CVE: CVE-2024-3400
    Vulnerability Type: Command Injection
    CWE: [[CWE-77]]
    Sources: Palo Alto Networks Security Advisory
    Exploited in the wild: Yes, Palo Alto Networks is aware of a limited number of attacks that leverage the exploitation of this vulnerability.

    Issue Summary

    A severe command injection vulnerability identified as CVE-2024-3400 affects the GlobalProtect gateway feature of PAN-OS, allowing unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability impacts specific versions of PAN-OS (PAN-OS 11.1 < 11.1.2-h3, PAN-OS 11.0 < 11.0.4-h1, PAN-OS 10.2 < 10.2.9-h1) with the configurations for both GlobalProtect gateway and device telemetry enabled.

    Technical Key Findings

    The vulnerability allows for OS command injection through improperly neutralized special elements in commands. This flaw can be exploited remotely without user interaction due to its network-based attack vector and low complexity.

    Vulnerable Products

    Affected products include certain versions of PAN-OS 10.2, 11.0, and 11.1 when both GlobalProtect gateway and device telemetry are enabled.

    Impact Assessment

    Exploitation could lead to complete system compromise, enabling attackers to disrupt operations or steal sensitive information.

    Patches or Workarounds

    Hotfix releases for affected PAN-OS versions are expected by April 14, 2024. A mitigation through Threat ID 95187 is available for those with Threat Prevention subscriptions, or by temporarily disabling device telemetry until the device is upgraded to a fixed PAN-OS version.

    Tags

    #PaloAltoNetworks #CVE-2024-3400 #Cybersecurity #CommandInjection #NetworkSecurity

  12. Wall-Escape Vulnerability Analysis: Implications and Mitigation Strategies

    Date: February 27, 2024
    CVE: CVE-2024-28085
    Vulnerability Type: [[Command Injection]]
    CWE: [[CWE-77]], [[CWE-78]], [[CWE-88]]
    Sources: [SANS Wall-Escape (CVE-2024-28085)](https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt

    Issue Summary

    Wall-Escape (CVE-2024-28085) unveils a critical flaw in the wall command from the util-linux package, allowing unprivileged users to execute command-line arguments without proper escape sequence filtering. This vulnerability has existed since 2013, posing a significant risk on systems where wall is setgid and mesg is set to 'y', notably Ubuntu 22.04 and Debian Bookworm.

    Technical Key findings

    The flaw arises from the mishandling of command-line arguments (argv), which are not sanitized for escape sequences. This oversight enables attackers to inject arbitrary text onto terminals of other users, potentially leading to information leakage or clipboard alteration. The vulnerability is exploitable through crafted wall command executions, leveraging system features to extract sensitive information such as user passwords.

    Vulnerable products

    • All versions of util-linux since 2013
    • Specifically impactful on:
      • Ubuntu 22.04
      • Debian Bookworm

    Impact assessment

    Successful exploitation can lead to unauthorized information disclosure and manipulation of terminal sessions. On Ubuntu 22.04, attackers can deceive users into revealing passwords. The vulnerability also enables clipboard content alteration on certain terminal emulators.

    Patches or workaround

    No specific patches were mentioned for CVE-2024-28085. Users are advised to restrict access to the wall command and monitor systems for unusual terminal behavior indicative of exploitation attempts.

    Tags

    #CVE-2024-28085 #CommandInjection #Ubuntu #Debian #InformationDisclosure #util-linux #TerminalSecurity

  13. "🚨 #QNAPAlert: Multiple Vulnerabilities Unveiled Across QNAP Devices 🚨"

    Recent security advisories highlight critical vulnerabilities in QNAP NAS systems, potentially affecting thousands of users globally. These flaws range from command injection to SQL injection. 🛡️💻

    Highlights:

    • QSA-23-47 addresses a command injection vulnerability, enabling attackers to execute arbitrary commands.
    • QSA-23-30 and QSA-24-03 reveal OS injection and improper access control issues.
    • QSA-24-05 warns of an OS command and SQL injection vulnerability flaw, granting authenticated users to inject malicious code via a network vector.

    Mitigation: Users are urged to update their devices immediately to the latest firmware to protect against these vulnerabilities.

    Tags: #CyberSecurity #Vulnerability #QNAP #NAS #CommandInjection #SQLInjection #DataProtection #FirmwareUpdate 🛠️🔐

    Source: QNAP Security Advisories & HKCERT Bulletin

    #InfoSecExchange #TechTalks 💬🔍

  14. "🔥 pfSense Security Alert: Critical Vulnerabilities Uncovered by SonarCloud 🛡️"

    SonarCloud's vigilant scanning reveals two critical vulnerabilities in pfSense, a widely used open-source firewall: XSS (CVE-2023-42325) and Command Injection (CVE-2023-42326). These vulnerabilities, if exploited, could allow attackers to execute arbitrary commands on pfSense appliances, highlighting the importance of continuous security vigilance even within trusted network perimeters. Thanks to swift action by Netgate, patches are now available. A reminder to always keep your systems updated!

    📚 Source: Oskar Zeino-Mahmalat's article on SonarSource SonarSource Blog

    Tags: #pfSense #Cybersecurity #Vulnerabilities #XSS #CommandInjection #Netgate #SonarCloud #SecurityPatch 🚨🔒💻

  15. It's quite fun seeing more and more argument injection attacks popping up in the wild. This time it's tcpdump: seclists.org/fulldisclosure/20

    #commandinjection #cve

  16. I've had my first :github: CodeQL query merged into the experimental section of the official CodeQL rules!

    lnkd.in/dk_tTiQZ (and a "local" variant, lnkd.in/dP88QJwa).

    That's query ids java/command-line-injection-extra and java/command-line-injection-extra-local

    They spot something the existing :java: command injection query does, but in a way that's more robust to unusual code.

    It’s an edge case, but one that was important to a customer.

  17. 💉 #commandinjection is a type of #cyberattack that involves injecting malicious commands into a system through vulnerable input fields.

    🔒🛡️ Protecting against it is crucial to prevent unauthorized access, #databreaches, and potential system compromise.

    To learn more: bit.ly/45VGBah

    #commandinjectionattack #codeinjection #injectionattacks #owasp #applicationsecurity #vulnerabilities #waap #waf #apptrana #indusface

  18. 💉 #commandinjection is a type of #cyberattack that involves injecting malicious commands into a system through vulnerable input fields.

    🔒🛡️ Protecting against it is crucial to prevent unauthorized access, #databreaches, and potential system compromise.

    To learn more: bit.ly/45VGBah

    #commandinjectionattack #codeinjection #injectionattacks #owasp #applicationsecurity #vulnerabilities #waap #waf #apptrana #indusface

  19. 💉 #commandinjection is a type of #cyberattack that involves injecting malicious commands into a system through vulnerable input fields.

    🔒🛡️ Protecting against it is crucial to prevent unauthorized access, #databreaches, and potential system compromise.

    To learn more: bit.ly/45VGBah

    #commandinjectionattack #codeinjection #injectionattacks #owasp #applicationsecurity #vulnerabilities #waap #waf #apptrana #indusface

  20. Researchers hack Siri, Alexa, and Google Home by shining lasers at them - Enlarge (credit: Sugawara et al.)
    Siri, Alexa, and Google Assistant are vulnerable to attacks tha... more: arstechnica.com/?p=1595561 #commandinjection #voicecontrol #googlehome #biz&it #lasers #alexa #sire

  21. In February 2024, 174 #zeroday #vulnerabilities, including 64 #XSS vulnerabilities, were detected.

    100% of these zero-day vulnerabilities were blocked by #AppTrana's core rules (92%), premium rules, and custom rules(8%).

    Get the full report and protect yourself against the latest #cyberthreats: bit.ly/3TfmCx7

    #zerodayvulnerability #zerodaythreats #0day #cybersecurity #cyberattacks #sqlinjection #commandinjection #zerpdayexploit #ddos #botattacks #indusface

  22. In February 2024, 174 #zeroday #vulnerabilities, including 64 #XSS vulnerabilities, were detected.

    100% of these zero-day vulnerabilities were blocked by #AppTrana's core rules (92%), premium rules, and custom rules(8%).

    Get the full report and protect yourself against the latest #cyberthreats: bit.ly/3TfmCx7

    #zerodayvulnerability #zerodaythreats #0day #cybersecurity #cyberattacks #sqlinjection #commandinjection #zerpdayexploit #ddos #botattacks #indusface

  23. In February 2024, 174 #zeroday #vulnerabilities, including 64 #XSS vulnerabilities, were detected.

    100% of these zero-day vulnerabilities were blocked by #AppTrana's core rules (92%), premium rules, and custom rules(8%).

    Get the full report and protect yourself against the latest #cyberthreats: bit.ly/3TfmCx7

    #zerodayvulnerability #zerodaythreats #0day #cybersecurity #cyberattacks #sqlinjection #commandinjection #zerpdayexploit #ddos #botattacks #indusface