nasa / openmct

A web based mission control framework.
https://nasa.github.io/openmct/
Other
12.05k stars 1.25k forks source link

Ability code injections in [sub.nasa.gov] remote a webshell_executed #4420

Closed orangmuda closed 3 years ago

orangmuda commented 3 years ago

Summary

Introduce my name ANDRI I am currently a bughunter for a company, Hackerone LTD.

I did Penetration Testing on the nasa.gov domain and for days I tried to find security holes in the entire nasa.gov domain, and finally I got to that stage, I found a vulnerability that had a fatal impact on the network and web applications, this vulnerability can be used by attacker to take over the server as well as the database. IMG-20211101-WA0000_1

akhenry commented 3 years ago

This repository is for the Open MCT project specifically.

Please report issues with the nasa.gov domain to the NASA security operations center at soc@nasa.gov. Be prepared to report the specific details of any purported security vulnerabilities.

orangmuda commented 3 years ago

Nice for closed!