h0ffayyy (12)

Last Login: March 20, 2021
Assessments
2
Score
12

h0ffayyy's Latest (2) Contributions

Sort by:
Filter by:
5
Ratings
Technical Analysis

Fairly easy to exploit, but I wasn’t able to do more than send requests from the victim server. May be useful for an attacker to recon internal infrastructure.

My POC can be seen here: https://github.com/h0ffayyy/Jira-CVE-2019-8451

5
Ratings
Technical Analysis

The Dashboard Snapshot API allows an unauthenticated user to create dashboard snapshots. An attacker could generate enough snapshots to eventually fill up the disk on the Grafana server, causing the denial of service.

My proof of concept can be found here: https://github.com/h0ffayyy/CVE-2019-15043