Re: [Full-disclosure] Remote Command Execution in dotDefender Si

看板Bugtraq作者時間16年前 (2009/12/03 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
On 30 Nov 2009, at 07:48, John Dos wrote: > After passing the Basic Auth login you can create/delete applications. If Basic auth is the only protection, isn't dotDefender also vulnerable = to XSRF?=
文章代碼(AID): #1B5gjbQy (Bugtraq)
文章代碼(AID): #1B5gjbQy (Bugtraq)