This Metasploit module exploits two vulnerabilities in Sharepoint 2019 - an authentication bypass as noted in CVE-2023-29357 which was patched in June of 2023 and CVE-2023-24955 which was a remote com ...
Continue ReadingMarch 28, 2024
This Metasploit module exploits two vulnerabilities in Sharepoint 2019 - an authentication bypass as noted in CVE-2023-29357 which was patched in June of 2023 and CVE-2023-24955 which was a remote com ...
Continue ReadingMarch 28, 2024
Impact When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g., web server logs, brow ...
Continue ReadingMarch 28, 2024
Vulnerabilities for packages: ruby3.2-json-jwt,...Read More ...
Continue ReadingMarch 28, 2024
Vulnerabilities for packages: ruby3.2-json-jwt,...Read More ...
Continue ReadingMarch 28, 2024
Impact When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g., web server logs, brow ...
Continue ReadingMarch 28, 2024
Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security ri ...
Continue ReadingMarch 28, 2024
Vulnerabilities for packages: ruby3.2-json-jwt,...Read More ...
Continue ReadingMarch 28, 2024
Back to Main