Skip to content
#

absysnet

Here is 1 public repository matching this topic...

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/ endpoint. Successful exploitation can compromise active user sessions, exposing authentication tokens in HTML. The attack is limited to active sessions and is terminated if the user logs out.

  • Updated Nov 24, 2024
  • Python

Improve this page

Add a description, image, and links to the absysnet topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the absysnet topic, visit your repo's landing page and select "manage topics."

Learn more