Home New Trending Search
About Privacy Terms
Posts
's posts

I hope it's gonna be a fortinet zeroday, I'd like to se De Niro do /../ and then bypass the fix with /..;/

1 year ago 1 0 0 0

The question I often face handling that kind of bugs is weather having to target a specific user (admin) with social engineering would make the attack complexity High or is User interaction "required" enough here to have a realistic CVSS score.

1 year ago 0 0 1 0

In my opinion PR is None as it is a relfected XSS, the attacker does not need privileges to craft the payload and send it to an admin.

1 year ago 0 0 1 0
@lpi1
19 Followers 213 Following 3 Posts
Posts Following