Skip to content

Instantly share code, notes, and snippets.

@andrewaeva
andrewaeva / gist:beb92d3d2f1c5672dbda5050e323f6a0
Created April 15, 2020 13:16
Multiple vulnerabilities in ONLYOFFICE Document Server 5.5.0.
CVE-2020-11534
[Suggested description]
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
An attacker can craft a malicious .docx file, and exploit the NSFileDownloader
function to pass parameters to a binary (such as curl or wget) and remotely execute code on
a victim's server.
------------------------------------------

Keybase proof

I hereby claim:

  • I am andrewaeva on github.
  • I am andrewa (https://keybase.io/andrewa) on keybase.
  • I have a public key ASCTy9-WJjWVcjll5Nf8ZCczTNww0DUZDdiMue1hHcHR8go

To claim this, I am signing this object:

# -*-coding:utf-8-*-
import json
import pandas as pd
import r2pipe as r2
dataframe = pd.DataFrame(columns=['name_function', 'opcodes'])
r2p = r2.open('example')
r2p.cmd('aaa')
afl = json.loads(r2p.cmd('aflj'))

Keybase proof

I hereby claim:

  • I am andrewaeva on github.
  • I am andrewa (https://keybase.io/andrewa) on keybase.
  • I have a public key whose fingerprint is 6277 2D45 42CE 957F 003F A433 BF03 8372 FC22 D314

To claim this, I am signing this object:

@andrewaeva
andrewaeva / keybase.md
Created July 4, 2015 09:36
keybase.md

Keybase proof

I hereby claim:

  • I am andrewaeva on github.
  • I am andrewa (https://keybase.io/andrewa) on keybase.
  • I have a public key whose fingerprint is 8131 05DF D658 5635 3072 0785 0E84 C1D8 D99C 78DD

To claim this, I am signing this object: