Supervisor Supervisord XML-RPC Remote Code Execution (CVE-2017-11610)

A remote code execution (RCE) vulnerability exists in the XML-RPC server of supervisord. The vulnerability is due to lack of validation on requested XML-RPC methods. A remote attacker can exploit this vulnerability to execute arbitrary code via a specially crafted XML-RPC request.

from Check Point Update Services Advisories http://ift.tt/2k5pgIv

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...