Vulnerability Management

Blog Archive Tag

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines
Vulnerability Management
  • Introduction to Cross-Site Scripting

    Introduction to Cross-Site Scripting

    By Raxis Research Team This video covers the basics of cross-site scripting, including reflected, stored, and DOM-based XSS as well as remediation to protect against these attacks. October 29, 2021
  • Nagios XI Stored Cross-Site Scripting (XSS): CVE-2021-38156

    Nagios XI Stored Cross-Site Scripting (XSS): CVE-2021-38156

    By Raxis Research Team Nagios is open-source network and system monitoring software. Raxis’ Matt Dunn has discovered a cross-site scripting vulnerability that could leave users open to attack. September 17, 2021
  • PRTG Network Monitor Stored Cross-Site Scripting Vulnerability (CVE-2021-29643)

    PRTG Network Monitor Stored Cross-Site Scripting Vulnerability (CVE-2021-29643)

    By Raxis Research Team Raxis lead penetration tester Matt Dunn uncovers a new vulnerability in the PRTG Network Monitor (CVE-2021-29643). Read more here. August 20, 2021
  • JavaScript Execution to Display User's Cookie in an Alert Box

    ManageEngine Applications Manager Stored Cross-Site Scripting Vulnerability (CVE-2021-31813)

    By Raxis Research Team Raxis’ Matt Dunn has discovered another ManangeEngine cross-site scripting (XSS) vulnerability, this time in the Applications Manager product (CVE-2021-31813). June 25, 2021
  • Unescaped JavaScript Tags

    ManageEngine Key Manager Plus Cross-Site Scripting Vulnerability (CVE-2021-28382)

    By Raxis Research Team Raxis’ Lead Penetration Tester Matt Dunn discovers another cross-site scripting vulnerability in Zoho’s MangeEngine Key Manager Plus (CVE-2021-28382). June 11, 2021
  • Cross-Site Scripting Vulnerability in ManageEngine AD Self Service Plus (CVE-2021-27956)

    Cross-Site Scripting Vulnerability in ManageEngine AD Self Service Plus (CVE-2021-27956)

    By Raxis Research Team Raxis lead penetration tester Matt Dunn has uncovered a new cross-site scripting vulnerability in Manage Engine AD Self Service Plus (CVE-2021-27956). Find out more here. May 20, 2021