Security Advisories
A collection of security advisories disclosed by Evolved Threat researchers.
Apple Music Arbitrary JavaScript Execution
Apple Music Arbitrary JavaScript Execution
DESCRIPTION
A vulnerability in Apple Music for Windows allows arbitrary JavaScript execution through maliciously crafted content.
AFFECTING
- Apple Music • TBD for Windows
BYOB (Bring Your Own Botnet) Unauthenticated Remote Code Execution
BYOB (Bring Your Own Botnet) Unauthenticated Remote Code Execution
DESCRIPTION
An unauthenticated remote code execution vulnerability in BYOB (Bring Your Own Botnet) allows attackers to execute arbitrary code.
AFFECTING
- BYOB (Bring Your Own Botnet) • All versions
Havoc C2 Team Server Unauthenticated SSRF
Havoc C2 Team Server Unauthenticated SSRF
DESCRIPTION
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Havoc C2 Team Server allows attackers to make arbitrary HTTP requests.
AFFECTING
- Havoc C2 Team Server • All versions
Pexip Infinity Connect Arbitrary JavaScript Execution
Pexip Infinity Connect Arbitrary JavaScript Execution
DESCRIPTION
A vulnerability in Pexip Infinity Connect allows arbitrary JavaScript execution through the application's interface.
AFFECTING
- Pexip Infinity Connect • 1.13.0 for Windows, macOS, Linux, Android, iOS
CHAOS RAT Multiple Remote Code Execution Vulnerabilities
CHAOS RAT Multiple Remote Code Execution Vulnerabilities
DESCRIPTION
Multiple remote code execution vulnerabilities in CHAOS RAT allow attackers to execute arbitrary code on affected systems.
AFFECTING
- CHAOS RAT • All versions
Maltego XML External Entity Injection
Maltego XML External Entity Injection
DESCRIPTION
A vulnerability in Maltego allows XML external entity injection attacks through malformed input.
AFFECTING
- Maltego • 4.2.12