Re: [FD] Citrix Gateway & Cloud MFA - Insufficient Session Validation Vulnerability

2023-07-16 Thread Jens Timmerman
Hi, On 03/07/2023 16:59, i...@esec-service.de wrote: Document Title: === Citrix Gateway&Cloud MFA - Insufficient Session Validation Vulnerability Technical Details & Description: An insufficient session validation web vulnerability was discovered i

[FD] WBCE - Stored XSS

2023-07-16 Thread Andrey Stoykov
# Exploit Title: WBCE - Stored XSS # Date: 07/2023 # Exploit Author: Andrey Stoykov # Version: 1.6.1 # Tested on: Windows Server 2022 # Blog: http://msecureltd.blogspot.com Steps to Exploit: 1. Login to application 2. Browse to following URI "http://host/wbce/admin/pages/intro.php"; 3. Paste XSS