Get a Pentest and security assessment of your IT network.

News

Severe Swagger Remote Code Execution flaw compromises NodeJS, Ruby, PHP, Java

An unpatched remote code execution vulnerability (CVE-2016-5641) in the Swagger API framework has been publicly disclosed. Swagger is a representation of RESTful API that allows developers to get interactive documentation, client SDK generation and discoverability. The vulnerability is easy to exploit due to the availability of a Metasploit module released by the security researcher Scott Davis. Injectable parameters in Swagger code generators allow attackers to remotely execute code across NodeJS, PHP, Ruby, and Java.”]

Source: http://securityaffairs.co/wordpress/48679/hacking/swagger-rce-flaw.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Russian cybercriminal Roman Seleznev gets another prison sentence