Exploit for CVE-2019-11510 (LFI in Pulse Secure)
Copy link to “Exploit for CVE-2019-11510 (LFI in Pulse Secure)”Sniper can now exploit a Local File Inclusion in Pulse Connect Secure (CVE-2019-11510).
These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
Sniper can now exploit a Local File Inclusion in Pulse Connect Secure (CVE-2019-11510).
The Deep Website Scanner will now generate more screenshots to simplify the reporting flow.
We added the possibility to clone an existing Pentest Robot.
Website Scanner findings that have been automatically validated by our scanner will be marked with the Confirmed tag.
Sniper can now exploit an RCE in the Open Management Infrastructure (OMI) agent that is preconfigured in the Linux VM deployed on Azure (CVE-2021-38647).
Sniper can now exploit an Unauthenticated RCE in VMware vCenter (CVE-2021-21972).
Sniper can now exploit an RCE in Atlassian Confluence (CVE-2021-26084).
The Network Scanner can now detect SSRF in vRealize Operations Manager API (CVE-2021-21975).
The Network Scanner can now detect if Modern Events Calendar Lite is vulnerable to an Unauthenticated Events Export (CVE-2021-24146).
Now you can limit the maximum requests (per second) for the Website Scanner. Check the Engine Options → Limits → Requests per second.
The Network Scanner can now detect RCE in VMware vCenter (CVE-2021-21985).
The Network Scanner can now detect XSS in the ProxyOracle exploit (CVE-2021-31195).
We added the possibility to manually reset the API key.
The URL Fuzzer can now do recursive searches by running automatically inside all the directories already discovered.
The WordPress Scanner can now search for config backups, database exports, or TimThumbs.
Added the possibility to add targets using the CIDR notation (eg. 192.168.1.0/24).
The Network Scanner can now detect CVE-2018-13379 – path traversal in FortiGate SSL VPN appliance.
The HTTP Request Logger tool can now be accessed via the API.
The Network Scanner can now detect Node.js Systeminformation Command Injection (CVE-2021-21315).
The Network Scanner can now detect Remote Code Execution in Microsoft Exchange Server (CVE-2021-28480).