HomeHomeAll tags

Tag: Cybersecurity

Spring Cloud Config Server directory traversal vulnerability CVE-2020-5410

June 17, 2020
  • Java
  • Spring
  • Vulnerability analysis
  • Cybersecurity
  • Spring Could Config Server has a directory traversal vulnerability CVE-2020-5410. The vulnerability is due to the direct splicing of the obtained name and label in the MVC architecture without any filtering. It can be performed with the base address in the configuration file. Backtrack at any position and read the file.

    Several methods to download and execute malicious code through command

    January 03, 2018
  • Shell
  • Cybersecurity
  • Penetration test
  • The execution of malicious code on the target host can be divided into uploading/downloading and executing malicious code and fileless remote malicious code execution. Next, let's summarize some methods of downloading and executing malicious code in Linux and Windows.

    © 2021, Built with Gatsby