❌

Normal view

[0day-rubbish] StreamSets Transformer 3.17.0 auth-mode none fallback and un-sandboxed ScalaDTransform execution to container root (8.1 primary)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
StreamSets Transformer, the Spark-engine data-pipeline platform from
StreamSets Inc. (subsequently acquired by IBM), verified on version 3.17.0
analysed from the official container image.

Type: failing-open authentication plus un-sandboxed code injection. On the
web tier, CWE-306 and CWE-1188 with CWE-285 on the authorisation side: when
the effective http.authentication value...

[0day-rubbish] RCDevs WebADM 2.4.14 authenticated log viewer sid command injection to webadm uid 999 code execution (7.2)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in RCDevs WebADM
2.4.14, Freeware Edition, the closed-source IAM/MFA management platform from RCDevs
Security SA (Luxembourg) that fronts the vendor's OpenOTP, SpanKey and TiQR
authentication products.

Type: OS command injection (CWE-78, with CWE-20 and CWE-116 contributing, and
CWE-732/CWE-276 and CWE-250 added for two auxiliary conditions). The administrator
console log...

[0day-rubbish] Maian Cart 3.8 addBanners unrestricted banner upload to PHP webshell and administrator command execution (7.2 primary, PR:H)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Maian
Cart 3.8, the self-hosted PHP shopping-cart system from Maian Media (Maian
Script World), verified end to end against a real installation of that
version.

Type: unrestricted upload of a file with a dangerous type (CWE-434), realized
as OS command execution (CWE-78) through an attacker-supplied PHP webshell,
with CWE-269 bearing on the execution privilege context. The...

[0day-rubbish] IPConfigure Orchid VMS 26.3.0 authenticated DNF repository GPG-key property command injection to root (7.2)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in
IPConfigure Orchid VMS, installed as Orchid Recorder, version 26.3.0.

Type: OS command injection (CWE-78, with CWE-20 bearing on it because no
character validation exists anywhere on the path; CWE-250 bears on the
result). The server property package.dnf.repo.gpg_key, the URL or path of
the GPG key signing the vendor RPM repository, is written through the
authenticated...

[0day-rubbish] Circutor LineEds 24.11.14-r0 unauthenticated pwrstudio events.xml shellExecute command injection (9.8)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the pwrstudio
daemon shipped in Circutor LineEds (Line Energy Data System) industrial energy gateway
firmware 24.11.14-r0, engine variant pss0. Circutor S.A. is in Spain; the appliance sits
between metering and power-quality instrumentation on one side and an energy-management
or SCADA back office on the other.

Type: operating-system command injection (CWE-78) reached without...

[0day-rubbish] Asustor ADM 3.5.9.RWM1 (AS602T) music.cgi act=live stored-filename command injection reaching system() (8.8 primary, PR:L)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in the
media handler of the ADM (ASUSTOR Data Master) management portal, verified by
static analysis on the AS602T running ADM 3.5.9.RWM1 (x86-64, first-
generation G1 firmware line, from the distributed image
ADM_X64_G1_3.5.9.RWM1_AS602T.img).

Type: OS command injection (CWE-78), enabled by an argument-quoting breakout
(CWE-88) and by an incomplete list of disallowed values...

[0day-rubbish] Advantech WebAccess Node 9.2.3 unauthenticated CrystalRpt.aspx file upload and path traversal to code execution in w3wp.exe (9.8)

6 October 2026 at 17:44

Posted by disclosure via Fulldisclosure on Oct 06

0day Rubbish Research Team is publicly disclosing a vulnerability in Advantech
WebAccess Node 9.2.3, the closed-source industrial SCADA/HMI web server from
Advantech (Taiwan).

Type: unrestricted file upload (CWE-434) compounded by path traversal (CWE-22), on
a page that performs no authorization decision at all (CWE-306). CWE-73 and CWE-862
also map; CWE-250/CWE-269 apply conditionally where the pool runs at high
privilege. In the WaCrpt ASP.NET...

SEC Consult Research 20261001 :: Arbitrary Email sender spoofing in Apple iCloud mail

6 October 2026 at 17:44

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Research Announcement < 20261001 >
=======================================================================
title: Arbitrary Email sender spoofing in Apple iCloud mail
product: Apple iCloud mail (SMTP submission service)
vulnerable version: iCloud mail infrastructure (cloud service)
fixed version: Fixed by Apple (verified by SEC Consult, 2025-12-09)
CVE number: None...

SEC Consult SA-20260924-0 :: Multiple Vulnerabilities in Paessler PRTG Network Monitor #CVE-2026-4637 #CVE-2026-4638

6 October 2026 at 17:44

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 06

SEC Consult Vulnerability Lab Security Advisory < 20260924-0 >
=======================================================================
title: Multiple Vulnerabilities
product: Paessler PRTG Network Monitor
vulnerable version: <26.2.120.1449
Β  Β  Β  fixed version: 26.2.120.1449
Β  Β  Β  Β  Β CVE number: CVE-2026-4637, CVE-2026-4638
Β  Β  Β  Β  Β  Β  Β impact: high
homepage:...
❌