|
You are here |
buer.haus | ||
| | | | |
nv1t.github.io
|
|
| | | | | I've identified a security concern within the self-hosted file sharing tool ProjectSend in the current version r1605. By exploiting a chain of vulnerabilities - including Cross-Site Scripting (XSS), Insecure Direct Object Reference (IDOR), and weaknesses in its change password implementation - an authenticated attacker can force a logged-in user to unknowingly change their account password, by clicking a link. But let me explain the attack in detail. | |
| | | | |
artsploit.blogspot.com
|
|
| | | | | In December 2015, I found a critical vulnerability in one of PayPal business websites ( manager.paypal.com ). It allowed me to exe... | |
| | | | |
blog.kotowicz.net
|
|
| | | | | A blog on security, malware, cryptography, pentesting, javascript, php and whatnots | |
| | | | |
adamj.eu
|
|
| | | This is a blog post version of the talk I gave at DjangoCon Europe 2019 on the 10th April. | ||