❌

Normal view

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path
without credential override (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Royal Server 5.04.50529.0.

Type: Local privilege escalation to LocalSystem on the execution path without credential override (CWE-250)
CVSS: 7.2...

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote
escaping (8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
core-admin 1.0.164 (build 16468).

Type: Systemic shell command injection via ineffective quote escaping (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)...

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective)
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
OP5 Monitor 9.20.

Type: Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
QuantaStor 6.8.3.018.

Type: Command injection in the alert-mail command via the smtpPassword field (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT
AUTHORITY\SYSTEM (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
SmarterMail 100.0.9693 (Build 9693).

Type: Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (CWE-250)
CVSS: 7.2...

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded
credentials leading to OS command execution (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6).

Type: Unauthenticated SOAP with hard-coded credentials leading...

[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading
to JNDI remote class loading (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Accurate Online Private Cloud on-prem (current).

Type: Unauthenticated Hessian deserialization leading to JNDI remote class loading...

[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
DBxtra .NET 13.1.1.0.

Type: Unauthenticated SOAP API to xp_cmdshell code execution (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: unauthenticated remote code execution as...

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE β€” Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

8 September 2026 at 17:30

Posted by Surf free on Sep 08

Tozed ZLT X300 5G CPE Router firmware 6.01.3 contains an OS command
injection vulnerability (CWE-78) in the TR-069/CWMP client daemon
(netcwmpd). The IPPingDiagnostics Host parameter is passed unsanitized into
sprintf, which constructs a shell command executed via system_by_root() as
root.

An attacker operating a rogue LTE base station using SDR hardware (~$300)
can impersonate the carrier's Auto Configuration Server and inject
arbitrary...

CVE-2026-52307: Stored XSS in 1CMS v5.6

8 September 2026 at 17:24

Posted by ζ‡’-η™Œ-η—‡ο½ž via Fulldisclosure on Sep 08

CVE-2026-52307: 1CMS v5.6 Authenticated Stored XSS Vulnerability

Vulnerability Description
An authenticated stored cross-site scripting (XSS) vulnerability exists in the Column Management component of ClassCMS
1CMS v5.6. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title field.

- Vulnerability Type: Cross Site Scripting (XSS)
- Vendor: ClassCMS
- Affected Product: 1CMS v5.6
- Affected Component:...

HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556

4 September 2026 at 00:13

Posted by Nir Yehoshua on Sep 03

Hello Full Disclosure list,

Cipher Security Labs has published technical details for three
High-severity vulnerabilities affecting HP Easy Start for macOS. The
issues were coordinated with HP and are addressed in HP Easy Start
2.16.7.260722 and later under HPSBPI04124.

Research title:
Rooted in Trust: Breaking HP Easy Start’s macOS Privilege Boundaries

Affected product:
HP Easy Start for macOS

Affected versions:
Versions prior to...

Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Next.js 16.4.0-canary.13 contains a DNS rebinding TOCTOU Server-Side
Request Forgery vulnerability in the Image Optimizer's fetchExternalImage()
functionality.

Next.js attempts to prevent requests to private network resources by
resolving the supplied hostname and checking the resulting addresses using
isPrivateIp():

const records = await lookup(hostname, {
family: 0,
all: true,
hints: ALL,
})

const privateIps = records.map((record)...

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

O-CMS version 1.0.0 contains an authenticated OS command injection
vulnerability in the AI CLI configuration functionality. An authenticated
attacker with sufficient privileges can supply shell metacharacters and
additional commands through the ai_cli_script parameter of
/admin/settings/save.

When the configured AI provider is subsequently tested through
/admin/settings/test-ai, the attacker-controlled CLI value is executed in a...

Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

Flextype CMS contains a remote code execution vulnerability in the
interaction between the Entries API and Shortcodes::registerShortcodes().
The /api/v1/entries endpoint accepts an attacker-controlled entry
identifier that can contain path traversal sequences, allowing content
containing PHP code to be written outside the intended entries directory.

The /api/v1/query endpoint subsequently permits an attacker-controlled path
to reach...

Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

Flextype CMS v1.0.0-alpha.3 contains a stored server-side request forgery
(SSRF) vulnerability in its shortcode-processing functionality.

Attacker-controlled entry fields can be automatically processed by
Flextype's shortcode parser. The built-in fetch shortcode accepts an
attacker-controlled resource and passes the resulting value to the
server-side fetch() helper without sufficient destination restrictions.

An attacker...

Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

Flextype CMS v1.0.0-alpha.3 contains an arbitrary file-read vulnerability
in its stored shortcode processing functionality. Attacker-controlled entry
fields are automatically processed by the shortcode parser when global
shortcode processing is enabled.

The built-in filesystem shortcode accepts a file path and returns the
contents of the specified file without restricting the path to an approved
application directory.

An attacker...

Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

Flextype CMS v1.0.0-alpha.3 contains a stored code execution vulnerability
caused by the interaction between globally processed entry expressions, the
mutable registry object exposed to expressions, and the PHP entry directive.

Attacker-controlled entry fields are automatically processed as expressions
during entry retrieval. The expression environment exposes the
application's mutable registry() object, allowing an expression...

Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

Flextype CMS v1.0.0-alpha.3 contains an authentication validation
vulnerability in the API request-processing functionality. API endpoints
may declare access_token as a required parameter, but the
required-parameter validation only verifies that the corresponding key
exists in the supplied request data.

Authentication verification is subsequently performed inside an isset($data
['access_token']) condition. In PHP, isset()...

Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

Flextype CMS v1.0.0-alpha.3 contains a path traversal vulnerability in the
Entries copy functionality. An authenticated remote attacker can supply
directory traversal sequences within both the source id and destination
new_id parameters submitted to /api/v1/entries/copy.

Flextype constructs entry directory paths by directly concatenating the
supplied entry identifier with the configured entries directory without
sufficiently...

Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API

4 September 2026 at 00:13

Posted by Ron E on Sep 03

Description

Flextype CMS v1.0.0-alpha.3 contains a server-side request forgery (SSRF)
vulnerability in the expression-processing functionality exposed through
the /api/v1/query endpoint. An authenticated remote attacker can supply an
arbitrary URL to the exposed fetch() function, causing the Flextype server
to initiate an outbound HTTP request to an attacker-controlled destination.

The application does not sufficiently restrict the destination...
❌