Apache Superset Part II: RCE, Credential Harvesting and More

Apache Superset Part II: RCE, Credential Harvesting and More

Apache Superset is a popular open source data exploration and visualization tool. In a previous post, we disclosed a vulnerability, CVE-2023-27524, affecting thousands of Superset servers on the Internet, that enables unauthorized attackers to gain admin access to these servers....
Horde Webmail contains zero-day RCE bug with no patch on the horizon

Horde Webmail contains zero-day RCE bug with no patch on the horizon

Adam Bannister 01 June 2022 at 14:34 UTC Updated: 06 June 2022 at 12:56 UTC CSRF exploit requires person to open malicious e-mailA zero-day vulnerability in Horde Webmail allows attackers to take over the internet server and pivot to compromising...
Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)

Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)

A nonetheless unpatched vulnerability (CVE-2022-41352) in Zimbra Collaboration is being exploited by attackers to realize distant code execution on susceptible servers. About the vulnerability Zimbra Collaboration (previously Zimbra Collaboration Suite) is cloud-hosted collaboration software program suite that additionally consists of...
RCE Vulnerability In UnRAR Library Affected Zimbra Platform

RCE Vulnerability In UnRAR Library Affected Zimbra Platform

A extreme distant code execution vulnerability affected the Zimbra electronic mail shopper. The bug usually existed within the UnRAR library that might set off RCE on the Zimbra platform. Thankfully, the bug acquired a repair earlier than malicious exploitation. Zimbra...
New OpenSMTPD RCE Flaw Affects Linux and OpenBSD Email Servers

New OpenSMTPD RCE Flaw Affects Linux and OpenBSD Email Servers

OpenSMTPD has been discovered weak to yet one more essential vulnerability that would permit distant attackers to take full management over e mail servers working BSD or Linux working methods.OpenSMTPD, also called OpenBSD SMTP Server, is an open-source implementation of...

Multiple critical vulnerabilities in Exim email server software pose RCE risk

Msg spool assault menaceSecurity researchers at Qualys have uncovered a number of safety vulnerabilities in Exim, one of the crucial fashionable mail switch brokers used for public-facing email servers.During a full safety audit of Exim, the researchers discovered 21 vulnerabilities....