❌

Normal view

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path
without credential override (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Royal Server 5.04.50529.0.

Type: Local privilege escalation to LocalSystem on the execution path without credential override (CWE-250)
CVSS: 7.2...

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote
escaping (8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
core-admin 1.0.164 (build 16468).

Type: Systemic shell command injection via ineffective quote escaping (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)...

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective)
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
OP5 Monitor 9.20.

Type: Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
QuantaStor 6.8.3.018.

Type: Command injection in the alert-mail command via the smtpPassword field (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT
AUTHORITY\SYSTEM (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
SmarterMail 100.0.9693 (Build 9693).

Type: Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (CWE-250)
CVSS: 7.2...

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded
credentials leading to OS command execution (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6).

Type: Unauthenticated SOAP with hard-coded credentials leading...

[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading
to JNDI remote class loading (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Accurate Online Private Cloud on-prem (current).

Type: Unauthenticated Hessian deserialization leading to JNDI remote class loading...

[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
DBxtra .NET 13.1.1.0.

Type: Unauthenticated SOAP API to xp_cmdshell code execution (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: unauthenticated remote code execution as...

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE β€” Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

8 September 2026 at 17:30

Posted by Surf free on Sep 08

Tozed ZLT X300 5G CPE Router firmware 6.01.3 contains an OS command
injection vulnerability (CWE-78) in the TR-069/CWMP client daemon
(netcwmpd). The IPPingDiagnostics Host parameter is passed unsanitized into
sprintf, which constructs a shell command executed via system_by_root() as
root.

An attacker operating a rogue LTE base station using SDR hardware (~$300)
can impersonate the carrier's Auto Configuration Server and inject
arbitrary...

CVE-2026-52307: Stored XSS in 1CMS v5.6

8 September 2026 at 17:24

Posted by ζ‡’-η™Œ-η—‡ο½ž via Fulldisclosure on Sep 08

CVE-2026-52307: 1CMS v5.6 Authenticated Stored XSS Vulnerability

Vulnerability Description
An authenticated stored cross-site scripting (XSS) vulnerability exists in the Column Management component of ClassCMS
1CMS v5.6. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title field.

- Vulnerability Type: Cross Site Scripting (XSS)
- Vendor: ClassCMS
- Affected Product: 1CMS v5.6
- Affected Component:...
❌