cismet / cids-server-rest

1 stars 0 forks source link

SQL Injection via Nodes API #63

Open p-a-s-c-a-l opened 9 years ago

p-a-s-c-a-l commented 9 years ago

Get the children of a certain node from the dynamicchildren section of the node: cids-server-rest-legacy implementation executes arbitrary SQL posted via /nodes/{domain}/children, even without user authentication!