Get a Pentest and security assessment of your IT network.

News

Analysis of Struts Vulnerabilities in Parameters & Cookie Interceptors

Apache Struts vulnerabilities and back-to-back releases/security announcements S2-022/2014-0116/S2-020 have been released. These vulnerabilities let an attacker get to the internal properties of Struts. Exploit works by modifying the naming scheme of log files and the location where log files are stored to root directory, where Web application code is stored. When the attacker sends a request containing malicious script, this will get logged into the log file, which may have a name and extension of the attackers choice.”]

Source: https://securityintelligence.com/struts-vulnerabilities-analysis-parameters-cookie-interceptors-impact-exploitation/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

RasGas, The Second Victim!

News

Technical analysis of the Locker virus on mobile phones