Vulnerabilities
Using flv_stream.php file from vendor directory we can download any file.
1 MIN READ
Vulnerabilities
Using flv_stream.php file from vendor directory we can download any file.
1 MIN READ
Vulnerabilities
$_GET['name'] is not escaped and then displayed inside pop_editor_view.
1 MIN READ
Vulnerabilities
Items from $_REQUEST['settings'] are not escaped.
3 MIN READ
Vulnerabilities
$_GET['sm'] is not escaped.
1 MIN READ
Vulnerabilities
PHP filter_input() function with FILTER_VALIDATE_URL flag is used to validate url inside savefaq functionality.
1 MIN READ
Vulnerabilities
$_POST[ 'id' ] is not escaped. populate_download_edit_form() is accessible for every registered user.
1 MIN READ
Vulnerabilities
parse_str() function is used without second param so variables are set in current scope.
1 MIN READ
Vulnerabilities
If user has at least one not dismissed notice, we have reflected XSS.
2 MIN READ
From 0 to pentesting hero
We are used to the fact that websites contain links to another web services. But, can automatic redirection to external domain be harmful?
09-04-2019
3 MIN READ