o2platform/DefCon_RESTing

o2platform/DefCon_RESTing

Releases0
Stars53
Repository to hold materials for DefCon_RESTing presentation by Dinis, Abe and Alvaro

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrated by a request to (1) db/data/ext/GremlinPlugin/graphdb/execute_script or (2) db/manage/server/console/.

4.6 MEDIUM

js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search.