Templates v8.2.0 release update ๐๐
To update nuclei with the latest templates: ๐ป๐๐ฐ๐น๐ฒ๐ถ -๐๐
To run nuclei with newly added templates: ๐ป๐๐ฐ๐น๐ฒ๐ถ -๐ป๐
๐ง๐ฒ๐บ๐ฝ๐น๐ฎ๐๐ฒ๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐น๐ผ๐ด: https://t.co/loFl9SCoFU
#hackwithautomation#pentest#security#bugbounty
CVE-2021-27330 Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading brows... https://t.co/eZDQuzABSn
Just when you thought JSON was the one thing you could trust. My latest research on JSON interoperability vulnerabilities highlights the risks of inconsistent parser behavior (40+ parsers) and attacks to bypass business logic in microservice architectures. https://t.co/A3MQkLpAXe
#bugbountytips
An almost universal way to theft or overwrite arbitrary files on #android is sharing activities. You can find them in AndroidManifest.xml. They handle android.intent.action.SEND. Use the PoC from https://t.co/D9sfxKvyX7 (ctrl+f "EXTRA_STREAM") and test 4 scenarios: