[SECURITY] [DSA 5307-1] libcommons-net-java security update

- ------------------------------------------------------------------------- Debian Security Advisory DSA-5307-1 [email protected] https://www.debian.org/security/ ...

Continue Reading


libcommons-net-java – security update

ZeddYu Lu discovered that the FTP client of Apache Commons Net, a Java client API for basic Internet protocols, trusts the host from PASV response by default. A malicious server can redirect the Commo ...

Continue Reading


libcommons-net-java – security update

ZeddYu Lu discovered that the FTP client of Apache Commons Net, a Java client API for basic Internet protocols, trusts the host from PASV response by default. A malicious server can redirect the Commo ...

Continue Reading


CSRF allows attacker to post on behalf of victim

# Description Cross-Site Request Forgery (CSRF) is an attack that forces authenticated users to submit a request to a Web application against which they are currently authenticated. CSRF attacks explo ...

Continue Reading
An attacker can be post message in other memos page

# Description An attacker can be post malicious content to other user's memos page via POST request, attacker just add an `creatorID` into body request and send it with Burpsuite **Here is video poc* ...

Continue Reading
Cross Site Request Forgery in Create a Memo Functionality (POST /api/memo)

# Description I have discovered in Memos a CSRF Vulnerability (in Create a Memo Functionality (POST /api/memo). I have identified that it is possible to manipulate the actions of authenticated users b ...

Continue Reading
CSRF to add shortcuts to victim account

# Description Cross-Site Request Forgery (CSRF) is an attack that forces authenticated users to submit a request to a Web application against which they are currently authenticated. CSRF attacks explo ...

Continue Reading
CSRF to change user language preferences

# Description Cross-Site Request Forgery (CSRF) is an attack that forces authenticated users to submit a request to a Web application against which they are currently authenticated. CSRF attacks explo ...

Continue Reading

Back to Main

Subscribe for the latest news: