CISA Adds Two Web Shells to Exchange Server Guidance

CISA Adds Two Web Shells to Exchange Server Guidance
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2021-3466PUBLISHED: 2021-03-25

A flaw was found in libmicrohttpd in versions before 0.9.71. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data ...

CVE-2021-3467PUBLISHED: 2021-03-25

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

CVE-2021-26596PUBLISHED: 2021-03-25

An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is...

CVE-2021-26597PUBLISHED: 2021-03-25

An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=u...

shells exchange server guidance