Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
LibreNMS认证后远程代码执行(低于26.5.0版本)
projectblack.io
| 研究 |
#rce
|
#web-security
|
#command-injection
|
#librenms
|
#authenticated
摘要
Project Black 的 LibreNMS 系列研究第二篇:Libvirt 发现模块中未经净化的 exec 调用可导致认证后 RCE;此外还可通过可写二进制路径与 composer wrapper 参数注入实现代码执行。
发布时间
2026-06-13 02:35
收录时间
2026-07-05 06:03
原文 ↗
相关内容
LibreNMS < 26.3.0 认证后的 RCE 与 XSS 漏洞分析
(projectblack.io)
把邮件模板注入变成远程代码执行
(labs.cognisys.group)
How I could've taken over the production server of a Yahoo acquisition through command injection
(samcurry.net)
标签名称中包含什么?显然,JavaScript
(portswigger.net)
拖放即攻:利用ASCII字符攻击VS Code
(portswigger.net)
Arista NG 防火墙漏洞深入分析
(bishopfox.com)
返回