Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

When the Heat Gets to Your Database: A Refreshing SQL Injection Discovery in Z-Push

Summary

Recounts XBOW's SQL injection discovery in a Z-Push ActiveSync server: after URL, header and XML attempts failed, the hunt pivoted to the Basic Authentication mechanism, where the flaw surfaced.
Published
Collected

original ↗

Related coverage

back