Web Hack List

Collected research

The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance

Chains six weaknesses in the LogPoint SIEM appliance into unauthenticated remote code execution: proxy path routing that exposes internal endpoints, a hard-coded token signing secret, leaked credentials for a hidden super-user, an SSRF reaching a host-only API that hands out the admin secret, and a static key on exported alert rules that smuggles a payload into an eval.

Record

Researcher
Mehmet Ince and @mdisec
Published by
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mehmet Ince and @mdisec, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .