Vulnerabilities
$_POST['poll_id'] is not escaped properly.
2 MIN READ
Vulnerabilities
$_POST['poll_id'] is not escaped properly.
2 MIN READ
Vulnerabilities
By default it's possible to upload .html files. So we can put XSS there.
1 MIN READ
Vulnerabilities
Nonce token is not checked inside install_new_favicon() function.
1 MIN READ
Vulnerabilities
$_GET['cs-msg'] is not escaped.
1 MIN READ
Ctf
Example of hash length extension vulnerability
4 MIN READ
Vulnerabilities
googleapis.com domain is whitelisted by default.
1 MIN READ
Vulnerabilities
$_GET['vid'] is not escaped.
2 MIN READ
Vulnerabilities
Every registered user can change livefyre_site_id and livefyre_site_key.
1 MIN READ
From 0 to pentesting hero
The functionality of file upload is a key place where we should pay special attention to. If the attacker successfully sends and executes a malicious file, the whole server may be taken over.
12-03-2019
3 MIN READ