Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
GeoNetwork - PreAuth 远程代码执行
ethiack.com
| 研究 |
#rce
|
#open-source
|
#pre-auth
|
#xslt
|
#geospatial
|
#geonetwork
摘要
GeoNetwork 地理空间元数据目录被发现 4 个漏洞,包括缺失 @PreAuthorize 注解导致的未授权文件上传,以及 Saxon XSLT 处理器配置不当引发的远程代码执行。
发布时间
2026-08-31 00:00
收录时间
2026-08-31 20:18
原文 ↗
相关内容
SharePoint ToolShell – One Request PreAuth RCE Chain
(blog.viettelcybersecurity.com)
使用 ChatGPT 在 Web 浏览器中获取 XXE
(swarm.ptsecurity.com)
From DEF CON Research to Automated Supply Chain Defense, finding npx confusion vulnerabilities with npxconfuse
(lab.ctbb.show)
两个 WordPress 核心漏洞如何串联成未认证 RCE
(bugbunny.ai)
CVE-2026-8054 — dotCMS Core Publish Audit API SQL 注入
(aretiq.ai)
ToolShell - A Critical SharePoint Vulnerability Chain under Active Exploitation
(blog.viettelcybersecurity.com)
返回