Preview meta tags from the positive.security website.
Linked Hostnames
Search Engine Appearance
From XSS to RCE (dompdf 0day) | Positive Security
Using a still unpatched vulnerability in the PHP library dompdf (used for rendering PDFs from HTML), we achieved RCE on a web server with merely a reflected XSS vulnerability as entry point.
From XSS to RCE (dompdf 0day) | Positive Security
Using a still unpatched vulnerability in the PHP library dompdf (used for rendering PDFs from HTML), we achieved RCE on a web server with merely a reflected XSS vulnerability as entry point.
From XSS to RCE (dompdf 0day) | Positive Security
Using a still unpatched vulnerability in the PHP library dompdf (used for rendering PDFs from HTML), we achieved RCE on a web server with merely a reflected XSS vulnerability as entry point.
General Meta Tags
7- titleFrom XSS to RCE (dompdf 0day) | Positive Security
- charsetutf-8
- descriptionUsing a still unpatched vulnerability in the PHP library dompdf (used for rendering PDFs from HTML), we achieved RCE on a web server with merely a reflected XSS vulnerability as entry point.
- twitter:titleFrom XSS to RCE (dompdf 0day) | Positive Security
- twitter:descriptionUsing a still unpatched vulnerability in the PHP library dompdf (used for rendering PDFs from HTML), we achieved RCE on a web server with merely a reflected XSS vulnerability as entry point.
Open Graph Meta Tags
4- og:titleFrom XSS to RCE (dompdf 0day) | Positive Security
- og:descriptionUsing a still unpatched vulnerability in the PHP library dompdf (used for rendering PDFs from HTML), we achieved RCE on a web server with merely a reflected XSS vulnerability as entry point.
- og:imagehttps://cdn.prod.website-files.com/5f6498c074436c349716e747/622a16c50a40993e3b60f0be_dompdf_rce_cover_thumb.png
- og:typewebsite
Twitter Meta Tags
1- twitter:cardsummary_large_image
Link Tags
7- alternaterss.xml
- apple-touch-iconhttps://cdn.prod.website-files.com/5f6498c074436c50c016e745/5f7dd71edeeceb5d47162386_256_256.png
- preconnecthttps://fonts.googleapis.com
- preconnecthttps://fonts.gstatic.com
- shortcut iconhttps://cdn.prod.website-files.com/5f6498c074436c50c016e745/5f7ddb13deeceb266b162f8d_favicon-32x32_white.png
17- http://SECURITY.md
- https://github.com/KnpLabs/snappy
- https://github.com/dompdf/dompdf
- https://github.com/dompdf/dompdf/blob/master/SECURITY.md
- https://github.com/dompdf/dompdf/issues/2598