andreahn / voting-app

For GIT-CTF competition (COSE451) - Team 2
0 stars 3 forks source link

TEAM1 - vuln5 issue #9

Open Lanph3re opened 3 years ago

Lanph3re commented 3 years ago

-----BEGIN PGP MESSAGE-----

hQGMA9DdZhFVaoVEAQv/WuyWkauHrrVMg/vIJW3qZqSnVspPHMPKG/iPkYHtN0t7 54Xh/pTxsdpg2EWR21PppZn4aFRksUyWfjOWwDTKwiOadcHxyBJKSq+Gsqj+Z/fn Gh1xxyaHpRoS5GitpyeHLwYKECxtp3TpuQ4hMCz65xZQxDXtwFcvU2HTHbhiHc/H iPw2tdSOv4VkWXJ9cPnpDLRuY87jCh1oBAkQuvDAc+PRmgMfMNcK50CfTVSjfJOG SSvQo9x89S1idy9iQpnyXjcJAe6Vf0YTIruiZ06ZTf4ovVTyiXyZ84rzfFpi5aLm zWfXDxZmTiPiCZ7sPWgaDtwzNlCLnAaENyqr3N4zxDdQ4PQeyFa6ps2qkH6GCdlM DUoQaFqvuojk0+WzHpyE2qZHPRfIZsj9tvoV/vUL9sYz7kdvFv6uDG5OWg91ylE3 JQaKoQkPf+GEh4V7TKt2cpkNeqkQ33s56msbNUQ6hsi4YPGxkaHreqBErX2NDJWF kwyDypnChktgrm7MlFE7hQGMA7MoJ8VxJKKQAQwAwMd8k/MlX+qAyo+knP6vRykI Y/CcaMUdZcOIUj5h6N35rroLaY62Xxu0E4GnKFTAy2DDdtEO4at2SMYq0XRiCNzj nScZ95yhkAjnn7vJG8/73Gfj5sWdwFtYiddJRo5M4GsiyGOi9AhkOw//Wz5RSHCb UoE3KpcxgcbcN3bK/ZJxkUr9ZdOwuT9BKcFQ2nWe3FW7jQDbI/gFqkY2rs5YhJnf 2VZDvTa3Kjot8H86Fp9Zf/P1h5PODG8umy3pKdoP7ZS3o2hzqGKzTwZJGE5Nc4d+ 3hE/BSH6NBTKc/J0qa46OzpkJkkwuSfcUNJNHeqTTs1xjEYuRrMns/qAftm3TlX/ UoBMV4j6Xawoti1No71gRbo1Nik88d557qOK3dP9XJzp190nJfrPxnFOyjWPozhU m1OP/NypJ49h+fqdSVOAuw4G4lYa3ZSXIgs2S8fLd5naTGdYzMrvfyR8zkkNs7Hx cXS5Li87kar+WHwgdvc8SofYZjXniu9jY6GsglSQ0sE4Afl+EqIIlt+qpm1BCNRl hxmBoPeoSdqf1IUSBLj+UD5UjKfzgr9gNQr4N4B4NCb0FFFBZTa4tr9pQI/oLQXd ySWeZvxcrARirTxYpxtSkHUr6AR1UoTp9EmR//qJeYkGJ4JD7Fu37mS1DquB/Gv2 K/Os+so+7TtrQa50ef0eyuWLrJ2YIXPXE3zGDF6IMH4sXQcJcZdy5mInV67mTopa VgAZz2GoKxj7jmxJAh1gEvnRugqNMEgAkDMyOuOfqG7HhbSf+DHBfe/UauoXgcLU Jh7/yKaPwlfInl8tmx4NbVW9vjzjSIkN95+uQiELQadl1pxXg/mJZRVrLZ3Qvwkp LjcS8t0ZOZqRGUhg9IFdgWvrsLQIhN3DY1ziy9nTt1DTw49TX1vqnT+XOKipYKQW qreO4yRvTzBS36CLVaUkKPfbW/GYKNSf9D4rMSJhAr0KuSAh3kg3P6qO+6x9TBb1 3SkqqFiEtZPuOxndiXaPBCjRuAx1dr2voPrquG0JAe3TTbqTLbon+kn2cU+TydWM kb1fG5kGiXpjFYltged2WY5SiKFbb4VHvGiMoJcRn/r8EohGRaA2kxdWx5idCLah qwrBHSfZ7LoxHP9fDG6HWRKDsLkmht+4oqJ/Je25xcD1eGueSVEtc7pIO86QJLN0 Fmh5vKo72Teq =+CAE -----END PGP MESSAGE-----

Lanph3re commented 3 years ago

-----BEGIN PGP MESSAGE-----

hQGMA9DdZhFVaoVEAQv+KeRU94AJRWgyjQMSuaqD7vXuGAG4FO5jH8ftk0Wh4yel 5a74deWLWjnuHMZjDTgL56ioMReIN9jtbFU3e0uv6gQEzgFCgkD8ekHBsh2jS8MW OESzzoj/5OoIZ4VGGREw71tydTFIKm0cxH93MSfrFv4PbxQvovBXKonBFhKEUNOg d29N7rhP5R6bha7ZVGQK6P0+045GkX8CZILrZLm+eH5CnWFLxjYILNnwGXAeNWvD OUM4NTqzGfno0qTU03KT42cZEPYiWaaajje4HDOBhdqTH0qbY6pIy1bcGBZHADT8 mGUSakMsWTM1IQA4ZZOxdJGvmNRUWVSK+sxzmAzVzQ7VXYexJqsItBljAtPQRfnJ 6G9aPvWaGNwwUNQxnJPb1VUoAZUin6tVmCr6g02oIT+VLWcW/k4iAR4BKhtWFH1K uGat2aVJkXCl+tkulyWovHMh8I59dkdS9q4eodwG0zepsRfcv7+elqofqnRyj9gX KI7NXIX1zm6WyN2y6dsKhQGMA7MoJ8VxJKKQAQv+KMpEiWU+rYdP/rZzWsRKjz+X Qfpx/otSzuZqxe9w5fyVWZd5Gk6H77KtXkNheDNArDV7U+aDGD2wY6WuwpKmgWd2 n2qF4rzUzi9kZTMv20vf/4R7RuXG/VjDtn9hh1bQKtZsjqiZNzYnCTpAk2zDAZp+ 6j+GSeSgsDRbo7XhFCoeYu/cbrSHQ6VDBJTRqegp8avqUPzkniG1gz9HkuXl3x/G vZmMxnjJJQcLnGmFdCDpqJHT5nncTR2Laf1yamDp8DIPYZef361PwwUI9+CuGlKu DoD7/klVhdDLGrQfqALXKD1qlewTbC/hRiMJqO41l3eh87Bo16tXf0C3APU0t3YW vqD6aHMI/EPPBE7RwT7ctHjqVbUDAuALvILzCMIuCuHA5gcA5DSnuYRdnqT6ltq+ +ObI5VwruzbY6pRHQhECRKzRYjCVuRnhbqoNBWLxpk5ERR6F35Q5PU6sE7i3qVOI +LO25viANW1OMxZ/587iudlCm0W/FJubYC5ifC2Y0ukBM/WUrEmesTqPdnp7xbc0 HRUO+ZwJPSJYZ6K5w+af1yLv+dU34f4CEdaBNEZVac3h9i7vfzhPIknrk6CkfNCt WybbbAMyiEUDOqXyka8WB83a/gSUH86UijTr2yZHQIVRdRGduN+eDxlHpLQJHfQK NHCilAH/V5pvC0QP4SkUdBB+Lg7QEtKfUISg9wensrf823zwE6sR/sC0C1/VEytl ISU5wrT+vhTfcUG555AeAVZodQ1Tm0Ozqzn0A0EBikngBNIyl3txk34MXab0nozR HNbQ6beA6P5lr5NJh7C9FGqum78/WmdfuPK03NLyQs38b3zZoCChY4pyvBCzINlz Ka+5bhdP6n8DhFjRLfOmsrE/kWhtdOlNbz6ZobsZXHZbad2gPX++c3DRK1z78E0p O6wiEAREpbJU1qzrj+BY3hLegLx+GiPSgkGxqO4la42DGNkHt4a2oAw2VCqI//sW yxQF56rv6Bq/wuCj+9ax79VdwpVavHxjQSZzxJuWmJd5YT9iENVo+yVV7B+TTXDY Mp5yoo3H7lJV+XmQW/obj3dF8PzJ5OH8IKdpbu4jEwPNNfVukWEJE1RNkM5Y+RSd Tm5ba8rTFu6VyDU6uie2iYHWafi2aNJ5HNPUnc6ex8CuJbogvisU1CvghfG+eusK iVXUcyVpu8A3E07GMChH9gtuhxGc33Dl+7sXwA== =eeuC -----END PGP MESSAGE-----

glim2485 commented 3 years ago

[Unintended vulnerability patch] unintended SQL injection in voting updated commit e8e8584 + 3b3d006