Google

Monorail

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 20.11.2018 09:29:04
  • Zuletzt bearbeitet 21.11.2024 03:57:45

Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 20.11.2018 09:29:03
  • Zuletzt bearbeitet 21.11.2024 03:57:44

Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information abo...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 20.11.2018 09:29:02
  • Zuletzt bearbeitet 21.11.2024 03:40:49

Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information abou...