From 8e50dc63c5d376409f1142a1936d6af9cca30a96 Mon Sep 17 00:00:00 2001 From: e1a Date: Thu, 17 Oct 2024 20:14:32 +0200 Subject: [PATCH 1/2] DIVD-2024-00041 update --- _cases/2024/DIVD-2024-00041.md | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/_cases/2024/DIVD-2024-00041.md b/_cases/2024/DIVD-2024-00041.md index d15027b9..32dee503 100644 --- a/_cases/2024/DIVD-2024-00041.md +++ b/_cases/2024/DIVD-2024-00041.md @@ -2,7 +2,7 @@ layout: case title: "Progress Software WhatsUp Gold SQL Injection Authentication Bypass" author: Finn van der Knaap -lead: Stan Plasmeijer +lead: Finn van der Knaap excerpt: "A SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password" researchers: - Finn van der Knaap @@ -28,8 +28,16 @@ timeline: event: "DIVD finds fingerprint, preparing to scan." - start: 2024-10-14 end: - event: "Case opened and starting first scan." - + event: "Case opened." +- start: 2024-10-16 + end: + event: "Starting first scan." +- start: 2024-10-17 + end: + event: "Starting second scan." +- start: 2024-10-17 + end: + event: "Mails sent out." --- From b459d99e70ea1f63f48978770f1f9462536c9c6c Mon Sep 17 00:00:00 2001 From: e1a Date: Thu, 17 Oct 2024 21:02:03 +0200 Subject: [PATCH 2/2] automated --- _cases/2024/DIVD-2024-00041.md | 1 + 1 file changed, 1 insertion(+) diff --git a/_cases/2024/DIVD-2024-00041.md b/_cases/2024/DIVD-2024-00041.md index 32dee503..80376f21 100644 --- a/_cases/2024/DIVD-2024-00041.md +++ b/_cases/2024/DIVD-2024-00041.md @@ -8,6 +8,7 @@ researchers: - Finn van der Knaap - Stan Plasmeijer - Alwin Warringa +- Max van der Horst cves: - CVE-2024-6670 product: