Embedthis Appweb 7.0.1 protecting its site with digest authentication, vulnerable to CVE-2018-8715: an Authorization header with only username=admin skips the password check in authCondition, and the server answers with an authenticated session cookie.
Pas commencéDockercommit 6680c04x86_64 · aarch64Secret
Exploit CVE-2018-8715 to bypass Appweb's authentication as admin and read the protected page.
Le brief de ce lab se trouve dans son dépôt.