You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If there is an open selenium web driver, a remote attacker can send requests to the victims browser. In certain cases this can be used to set command line flags for the browser which can sometimes be used for command injection. When command injection fails, the local file system can still be accessed using the file:// URI.
If the command injection can be tested and confirmed in cases, that would make for a nice exploit module. Access to the remote file system could be a separate, auxiliary module.
If there is an open selenium web driver, a remote attacker can send requests to the victims browser. In certain cases this can be used to set command line flags for the browser which can sometimes be used for command injection. When command injection fails, the local file system can still be accessed using the
file://
URI.If the command injection can be tested and confirmed in cases, that would make for a nice exploit module. Access to the remote file system could be a separate, auxiliary module.
References:
The text was updated successfully, but these errors were encountered: