RCE and Complete Server Takeover of http://www.█████.starbucks.com.sg/
Critical
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
This report from @spaceraccoon demonstrated a valid attack resulting in RCE and full compromise of the target. The detailed and thorough report was especially helpful throughout the triage process, and ultimately helped us reproduce and resolve the issue as quickly as possible. The vulnerable site has been taken offline. We'd like to thank @spaceraccoon for the submission, and hope to continue to see reports like this in the future.
Actions:
Reported by
spaceraccoon
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Code Injection