">
 

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Iniciado por Candidosa2, Hoje at 20:18

Respostas: 0   |   Visualizações: 4

Tópico anterior - Tópico seguinte

0 Membros e 1 Visitante estão a ver este tópico.

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Notícia de segurança recolhida automaticamente.


A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.

Security firm TantoSec has published a working exploit chain targeting vulnerabilities


Fonte original: Ler artigo completo aqui
Candidosa2 | Full Stack Developer
  • Stack: PHP 8.x | SMF 2.1.x | OpenCart | Joomla | Wordpress
  • Empresa: Aplic Consultoria em Informática, Lda
  • Local: Matola, Moçambique
Atenção: Antes de aplicar qualquer modificação, faça BACKUP da sua base de dados!

Tags: