[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":48,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":55,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":61,"vulnerability-5134":68},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":41,"text":42,"link":43,"external":44,"targets":45,"cta":47,"variant":13,"campaign_id":41},"Office Hours #12 - 5 offensive security topics that actually matter","office-hours-12","[Live Office Hours, Wed Sept 30] 5 offensive security topics that actually matter","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_aPuMw5m2TEyAcn9ZEbE8uQ",true,[46],"\u002F","Save your spot",["Island",49],{"key":50,"params":51,"result":53},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":52},"{}",{"head":54},{},["Island",56],{"key":57,"params":58,"result":59},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":52},{"head":60},{},["Island",62],{"key":63,"params":64,"result":66},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":65},"{\"text-color\":\"gray\"}",{"head":67},{},{"id":69,"detectable_with":70,"vuln_details":77,"vuln_id":92,"name":93,"published":94,"updated":78},5134,{"tool":71,"engine":74},{"id":72,"name":73},1,"Network Scanner",{"id":75,"name":76},3,"OpenVAS",{"id":69,"codename":78,"description":78,"severity":79,"risk_description":80,"public_description":81,"public_recommendation":82,"recommendation":78,"references":83,"cvssv3":86,"epss_score":87,"epss_percentile":88,"cve":89,"in_cisa_catalog":9,"date":91,"software_type":78,"vendor":78,"product":78,"ptt_exploit_capabilities":78},null,"high","The All in One SEO - Best WordPress SEO Plugin enables authenticated users with aioseo_tools_settings privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugins configuration by uploading a backup .ini file in the section Tool > Import\u002FExport. However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution. An authenticated attacker might execute arbitrary code.","The WordPress plugin All in One SEO Pack is prone to a remote code execution (RCE) vulnerability.","Update to version 4.1.0.2 or later.",[84,85],"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fall-in-one-seo-pack\u002F#developers","https:\u002F\u002Fwpscan.com\u002Fvulnerability\u002Fab2c94d2-f6c4-418b-bd14-711ed164bcf1",8.8,0.53274,0.9895,[90],"CVE-2021-24307","2021-05-24T00:00:00Z","NETSCAN-OPENVAS-1.3.6.1.4.1.25623.1.0.146187","WordPress All in One SEO Pack Plugin \u003C 4.1.0.2 RCE Vulnerability","2021-06-29T00:00:00Z"]