CVE-2022-37703 : AMANDA 3.5.1 CALCSIZE OPENDIR PRIVILEGES MANAGEMENT

Description

In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vulnerability to know if a directory exists or not anywhere in the fs. The binary will use `opendir()` as root directly without checking the path, letting the attacker provide an arbitrary path.

References

http://www.amanda.org/

https://github.com/MaherAzzouzi/CVE-2022-37703

For More Information

MITRE

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2022-47767 : SOLAR-LOG GATEWAY UP TO 4.2.7/5.1.1 SLCORE BACKDOOR

CVE-2022-47767 : SOLAR-LOG GATEWAY UP TO 4.2.7/5.1.1 SLCORE BACKDOOR

Description A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.

CVE-2022-45808 : LEARNPRESS PLUGIN UP TO 4.1.7.3.2 ON WORDPRESS SQL INJECTION

CVE-2022-45808 : LEARNPRESS PLUGIN UP TO 4.1.7.3.2 ON WORDPRESS SQL INJECTION

Description SQL Injection vulnerability in LearnPress – WordPress LMS Plugin

CVE-2023-21795 : MICROSOFT EDGE REMOTE CODE EXECUTION

CVE-2023-21795 : MICROSOFT EDGE REMOTE CODE EXECUTION

Description Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21796. References https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21795 For More Information