<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Daniele Scanu on sk4</title>
    <link>/</link>
    <description>Recent content in Daniele Scanu on sk4</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 25 Aug 2023 14:23:40 +0200</lastBuildDate><atom:link href="/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>About</title>
      <link>/about/</link>
      <pubDate>Fri, 25 Aug 2023 15:26:21 +0200</pubDate>
      
      <guid>/about/</guid>
      
      
      
      
      
      
      
      <description>
          <![CDATA[ 
          
          <p>My name is Daniele (aka @sk4), I&rsquo;m a digital forensics expert. In my spare time I enjoy looking 👀 for new low level vulnerabilities and tasting new wines 🍷.</p>
<h4 id="articles" class="link-owner">
  <a href="/about/#articles" class="link">
      <svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512"><title>Link</title><path fill="none" d="M208 352h-64a96 96 0 010-192h64M304 160h64a96 96 0 010 192h-64M163.29 256h187.42" fill="none" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round" stroke-width="36"/></svg>
  </a>Articles
</h4><ul>
<li><a href="https://www.soteritsecurity.com/blog/2023/12/Zyxel_VPN_Client_Local_Privilege_Escalation_CVE-2023-5593.html" title="Local Privilege Escalation via Zyxel VPN Client" target="_blank" rel="nofollow noopener">Local Privilege Escalation via Zyxel VPN Client</a></li>
<li><a href="https://www.soteritsecurity.com/blog/2023/02/Basercms_CVE-2021-41243.html" title="Zip Slip to RCE on Basercms - CVE-2021-41243" target="_blank" rel="nofollow noopener">Zip Slip to RCE on Basercms - CVE-2021-41243</a></li>
<li><a href="https://www.soteritsecurity.com/blog/2023/01/CMS-Made-Simple_CVE-2021-40961.html" title="CMS Made Simple from SQL-injection to RCE - CVE-2021-40961" target="_blank" rel="nofollow noopener">CMS Made Simple from SQL-injection to RCE - CVE-2021-40961</a></li>
<li><a href="https://web.archive.org/web/20230205014927/https://blog.certimetergroup.com/it/articolo/security/have-fun-with-file-extension-and-upload" title="Have fun with file extension and file upload (cve-2019-16318)" target="_blank" rel="nofollow noopener">Have fun with file extension and file upload (cve-2019-16318)</a></li>
<li><a href="https://web.archive.org/web/20230412201822/https://blog.certimetergroup.com/it/articolo/security/weaponize--order-by--sqli-on-wordpress-form-maker-" title="Weaponize &lsquo;order by&rsquo; SQLi on WordPress Form Maker plugin (CVE-2019-10866)" target="_blank" rel="nofollow noopener">Weaponize &lsquo;order by&rsquo; SQLi on WordPress Form Maker plugin (CVE-2019-10866)</a></li>
<li><a href="https://web.archive.org/web/20230412164537/https://blog.certimetergroup.com/it/articolo/security/exploiting_richfaces_in_a_heavily_firewalled_box" title="Exploiting RichFaces CVE-2018-12533 in a heavily firewalled box" target="_blank" rel="nofollow noopener">Exploiting RichFaces CVE-2018-12533 in a heavily firewalled box</a></li>
<li><a href="https://web.archive.org/web/20230520172319/https://blog.certimetergroup.com/it/articolo/security/polyglot_phar_deserialization_to_rce" title="Polyglot PHAR&rsquo;s deserialization for backdoored RCE (CVE-2019-10867)" target="_blank" rel="nofollow noopener">Polyglot PHAR&rsquo;s deserialization for backdoored RCE (CVE-2019-10867)</a></li>
<li><a href="https://web.archive.org/web/20230520172319/https://blog.certimetergroup.com/it/articolo/security/CMS_Made_Simple_deserialization_attack_%28CVE-2019-9055%29" title="CMS Made Simple deserialization attack (CVE-2019-9055)" target="_blank" rel="nofollow noopener">CMS Made Simple deserialization attack (CVE-2019-9055)</a></li>
<li><a href="https://web.archive.org/web/20230520172321/https://blog.certimetergroup.com/it/articolo/security/sql_injection_in_pimcore_6.2.3" title="SQL injection in Pimcore 6.2.3" target="_blank" rel="nofollow noopener">SQL injection in Pimcore 6.2.3</a></li>
</ul>
<h4 id="contacts" class="link-owner">
  <a href="/about/#contacts" class="link">
      <svg xmlns="http://www.w3.org/2000/svg" class="ionicon" viewBox="0 0 512 512"><title>Link</title><path fill="none" d="M208 352h-64a96 96 0 010-192h64M304 160h64a96 96 0 010 192h-64M163.29 256h187.42" fill="none" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round" stroke-width="36"/></svg>
  </a>Contacts
</h4><ul>
<li>Email: ds[at]danielescanu[dot]it</li>
<li>Twitter: <a href="https://twitter.com/sk4pwn" title="@sk4pwn" target="_blank" rel="nofollow noopener">@sk4pwn</a></li>
<li>LinkedIn: <a href="https://www.linkedin.com/in/daniele-scanu/" title="Daniele Scanu" target="_blank" rel="nofollow noopener">Daniele Scanu</a></li>
</ul>

          
          
          
          
          
          ]]>
      </description>


    </item>
    
    <item>
      <title>CVEs</title>
      <link>/cves/</link>
      <pubDate>Fri, 25 Aug 2023 15:13:03 +0200</pubDate>
      
      <guid>/cves/</guid>
      
      
      
      
      
      
      
      <description>
          <![CDATA[ 
          
          <ul>
<li><strong>CVE-2023-5593</strong>: Local Privilege Escalation via Zyxel VPN Client (Out of Bound)
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5593" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://www.soteritsecurity.com/blog/2023/12/Zyxel_VPN_Client_Local_Privilege_Escalation_CVE-2023-5593.html" title="Blog post - Soter IT Security" target="_blank" rel="nofollow noopener">Blog post - Soter IT Security</a></li>
<li><a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-out-of-bounds-write-vulnerability-in-secuextender-ssl-vpn-client-software" title="Zyxel advisory" target="_blank" rel="nofollow noopener">Zyxel advisory</a></li>
<li><a href="/files/VPwN.pdf" title="Meethack conference">Meethack conference</a></li>
</ul>
</li>
<li><strong>CVE-2021-41243</strong>: Arbitrary File Write via Archive Extraction (Zip Slip)
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41279" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-BASERPROJECTBASERCMS-1316241" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2021-23340</strong>: Local File Inclusion on Pimcore
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23340" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1070132" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2021-23405</strong>: SQL Injection on Pimcore
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23405" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1316297" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2020-7759</strong>: SQL Injection on Pimcore
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7759" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-1017405" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-10763</strong>: SQL Injection on Pimcore
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10763" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-480391" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9693</strong>: SQL Injection on module ShowTime2 of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9693" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9692</strong>: Remote Code Execution on module ShowTime2 of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9692" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://www.exploit-db.com/exploits/46546" title="Exploit-db PoC" target="_blank" rel="nofollow noopener">Exploit-db PoC</a></li>
</ul>
</li>
<li><strong>CVE-2019-16317</strong>: Remote Code Execution through wrapper phar on Pimcore
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16317" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-451599" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-16318</strong>: File Extention restriction bypass on Pimcore
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16318" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-451598" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-10866</strong>: SQL Injection on Wordpress plugin Form Maker
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10866" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://www.exploit-db.com/exploits/46958" title="Exploit-db PoC" target="_blank" rel="nofollow noopener">Exploit-db PoC</a></li>
</ul>
</li>
<li><strong>CVE-2019-10867</strong>: Deserialization on CMS Pimcore
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10867" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://security.snyk.io/vuln/SNYK-PHP-PIMCOREPIMCORE-173998" title="Snyk reference" target="_blank" rel="nofollow noopener">Snyk reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9061</strong>: Deserialization on module ModuleManager of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9061" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9060</strong>: Unauthenticated Path Traversal on module CGExtensions of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9060" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9059</strong>: Command Injection on core of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9059" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9058</strong>: Deserialization on core of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9058" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9057</strong>: Deserialization on module FilePicker of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9057" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9056</strong>: Deserialization on module FrontEndUsers of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9056" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
</ul>
</li>
<li><strong>CVE-2019-9055</strong>: Deserialization on module DesignManager of CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9055" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://www.rapid7.com/blog/post/2019/11/15/metasploit-wrap-up-42/" title="Metasploit Wrap-Up" target="_blank" rel="nofollow noopener">Metasploit Wrap-Up</a></li>
<li><a href="https://www.rapid7.com/db/modules/exploit/multi/http/cmsms_object_injection_rce/" title="Metasploit Module PoC" target="_blank" rel="nofollow noopener">Metasploit Module PoC</a></li>
</ul>
</li>
<li><strong>CVE-2019-9053</strong>: SQL Injection on CMS Made Simple
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9053" title="Mitre reference" target="_blank" rel="nofollow noopener">Mitre reference</a></li>
<li><a href="https://www.exploit-db.com/exploits/46635" title="Exploit-db PoC" target="_blank" rel="nofollow noopener">Exploit-db PoC</a></li>
</ul>
</li>
</ul>

          
          
          
          
          
          ]]>
      </description>


    </item>
    
  </channel>
</rss>