Full admin access of a voting machine used in US (in 18 states) in under two minutes, without any software or hardware tools.
#DefCon #misconfiguration
https://twitter.com/i/status/1028437783050776576
#DefCon #misconfiguration
https://twitter.com/i/status/1028437783050776576
Forwarded from Bug Bounty Channel
Hacktivity from cdl
https://hackerone.com/reports/395296
Phone Call to XXE via Interactive Voice Response
https://hackerone.com/reports/395296
HackerOne
cdl published a vulnerability from ██████ on HackerOne: Phone Call...
| Summary |
|--|
> ████ is vulnerable to XXE due to the processing of DTDs
| Description |
|--|
> *"VoiceXML (VXML) is a digital document standard for specifying interactive media and voice...
|--|
> ████ is vulnerable to XXE due to the processing of DTDs
| Description |
|--|
> *"VoiceXML (VXML) is a digital document standard for specifying interactive media and voice...