SolarWinds Serv-u File Server Command Injection Vulnerability

September 27, 2021 No Comments
EIP-d3400c52 The Serv-U File Server supports site specific commands which may not be universally supported by all FTP clients. Among these is the SITE EXEC command which allows a user to execute programs and scripts remotely, if the execute permission is present on
Read More »

Foxit PhantomPDF loadHtmlView Context Level Bypass Vulnerability

August 23, 2021 No Comments
EIP-617871b4 The vulnerability exists within the JavaScript PDF API exposed by Foxit PhantomPDF. The loadHtmlView method of the app object invokes attacker-controlled JavaScript code in a privileged context. An attacker can create a specially crafted PDF file that will abuse this vulnerability
Read More »
1 6 7