Security Vulnerabilities
- CVEs Published In November 2021
Microsoft Excel Remote Code Execution Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Azure RTOS Information Disclosure Vulnerability
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.
Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.