Re: [Full-disclosure] Remote Command Execution in dotDefender Si
On 30 Nov 2009, at 07:48, John Dos wrote:
> After passing the Basic Auth login you can create/delete applications.
If Basic auth is the only protection, isn't dotDefender also vulnerable =
to XSRF?=
討論串 (同標題文章)
完整討論串 (本文為第 1 之 2 篇):