diff --git a/_cases/2024/DIVD-2024-00041.md b/_cases/2024/DIVD-2024-00041.md index d15027b9..80376f21 100644 --- a/_cases/2024/DIVD-2024-00041.md +++ b/_cases/2024/DIVD-2024-00041.md @@ -2,12 +2,13 @@ layout: case title: "Progress Software WhatsUp Gold SQL Injection Authentication Bypass" author: Finn van der Knaap -lead: Stan Plasmeijer +lead: Finn van der Knaap excerpt: "A SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password" researchers: - Finn van der Knaap - Stan Plasmeijer - Alwin Warringa +- Max van der Horst cves: - CVE-2024-6670 product: @@ -28,8 +29,16 @@ timeline: event: "DIVD finds fingerprint, preparing to scan." - start: 2024-10-14 end: - event: "Case opened and starting first scan." - + event: "Case opened." +- start: 2024-10-16 + end: + event: "Starting first scan." +- start: 2024-10-17 + end: + event: "Starting second scan." +- start: 2024-10-17 + end: + event: "Mails sent out." ---