RedTeam Recipes

Home

About

contact

services

hall of fame

questions

trusted partners

privacy policy

loading..
CVEApacheCVE-2021-38294

CVE-2021-38294: Apache Storm Nimbus Command Injection

By Zeyad Azima Introduction#CVE-2021-38294 is a Command Injection vulnerability that affects Nimbus server in apache storm in getTopologyHistory services, A successful crafted request to Nimbus server will result in exploitation for this vulnerability will lead to execute malicious command & takeover the server. The affected versions are 1.x prior to 1..

Read more
loading..
CVECVE-2021-44521

CVE-2021-44521: Apache Cassandra Remote Code Execution

By Zeyad Azima IntroductionCVE-2021-44521 is a vulnerability discovered in Apache Cassandra which allow an attacker to achieve remote command execution through UDFS & bypass the sandbox to execute the code on the server under specific configurations which let the attacker to takeover the server. CVSS:(Critical) https://nvd.nist.gov/vuln-metrics/cvss/v3..

Read more
loading..
CVECVE-2022-22733

Exploit Writing: CVE-2022-22733 Privilege Escalation & RCE

By Zeyad Azima IntroductionIn the previous blog from here, We have done analysis for CVE-2022-22733 and understand the root cause of the vulnerability & the issue in details. Now, It’s the time to develop an exploit for this vulnerability and take it more further than just escalating our privileges. The ExploitAs we know from the analysis that to explo..

Read more
loading..
CVECVE-2023-24815

CVE-2023-24815: Vert.x-Web Path Traversal Escape

By Zeyad Azima IntroductionA vulnerability discovered in Vert.x-Web known as CVE-2023-24815, a threat actor can exploit this vulnerability to escape the path filter leading to exfiltrate any class path resource or Path Traversal, When tunning on windows. CVE Information CVE-ID: CVE-2023-24815 NVD Published Date: 02/09/2023 NVD Last Modified: 02..

Read more
loading..
CVEIoTCVE-2021-42885

CVE-2021-42885: deviceMac Remote Command Injection

By Zeyad Azima IntroductionA vulnerability discovered in TOTOLINK EX1200T model known as CVE-2021-42885 which is a remote command injection through the deviceMac parameter, As a results a malicious user can control the device and achieve remote command execution RCE. (Note:Everything you obtain here is for educational purposes, Don't use or abuse any b..

Read more
12