Vulnerabilities
This POC demonstrates method for obtaining GPG private keys from gpg-agent memory under Windows. Normally this should be possible only within 10 minutes time frame (--default-cache-ttl value).
1 MIN READ
Vulnerabilities
This POC demonstrates method for obtaining GPG private keys from gpg-agent memory under Windows. Normally this should be possible only within 10 minutes time frame (--default-cache-ttl value).
1 MIN READ
Vulnerabilities
Obtain passwords from JetBrains IDE (like IntelliJ or PyCharm) and use those credentials inside TeamCity Continuous Integration Server
1 MIN READ
Vulnerabilities
If you have Burp Pro, issues will also appear inside Scanner tab. Interesting things will be highlighted.
1 MIN READ
Vulnerabilities
$_SERVER['PHP_AUTH_PW'] is directly passed to exec function.
1 MIN READ
Vulnerabilities
We can access registerExternalLog without any user credentials.
2 MIN READ
Vulnerabilities
$_GET['uploaddir'] is not escaped and passed to system() through $tmp_upload_dir.
1 MIN READ
Vulnerabilities
CVE-2017-11151 allows remote attackers to upload arbitrary files to the specified directories.
1 MIN READ
Vulnerabilities
When uploading a file, the FileUploadServlet class does not check the user-controlled fileName parameter using hasVulnerabilityInFileName function.
3 MIN READ
From 0 to pentesting hero
Retrieving parameters from the user and later displaying them on the website always carries risk of XSS attack. But can you perform such attack without using the HTML tag?
21-03-2019
3 MIN READ