Detect CORS misconfiguration in Website Scanner
Copy link to “Detect CORS misconfiguration in Website Scanner”We added to Website Scanner the capability to detect dangerous Cross-Origin Resource Sharing (CORS) configurations.
These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
We added to Website Scanner the capability to detect dangerous Cross-Origin Resource Sharing (CORS) configurations.
We added to Website Scanner the capability to detect Server-Side Template Injection.
Sniper can now exploit an RCE in Apache Struts (CVE-2018-11776).
Sniper can now exploit an RCE in the Oracle Weblogic server (CVE-2020-14883).
We added new notification triggers related to the status of a scan: Stopped by user, VPN Error, Auth Error, Conn Error, Aborted.
You can now send a notification to additional emails.
We added Webhooks so you can trigger outgoing HTTP POST requests from Pentest-Tools.com to your endpoints whenever certain events have happened
The Network Scanner can now detect if a MobileIron Core server instance is vulnerable to Log4Shell (CVE-2021-44228).
Sniper can now exploit an RCE in the Oracle Weblogic server (CVE-2018-2894).
Sniper can now exploit an RCE in the Zoho ManageEngine ADSelfService Plus (CVE-2021-40539).
The Network Scanner can now detect if an Elasticsearch server is vulnerable to Log4Shell (CVE-2021-44228).
The Network Scanner can now detect if a VMware vCenter instance is vulnerable to Log4Shell (CVE-2021-44228).
Sniper can now exploit an RCE in the Log4j logging library (CVE-2019-17571).
The Password Auditor can now discover weak credentials over the following protocols: MQTT, AMQP, STOMP.
The Network Scanner can now detect if an Apache HTTP Server is vulnerable to Server Side Request Forgery (SSRF) (CVE-2021-40438).
Sniper can now exploit a Path Traversal vulnerability in Grafana (CVE-2021-43798).
The Network Scanner can now detect if an Apache Druid instance is vulnerable to Log4Shell (CVE-2021-44228).
The Network Scanner can now detect if an Apache Flink instance is vulnerable to Log4Shell (CVE-2021-44228).
The Network Scanner can now detect if an Apache Solr instance is vulnerable to Log4Shell (CVE-2021-44228).