Exploitation Summary
EIP tracks 2 public exploits for CVE-2020-28458. PoCs published by fazilbaig1, Raka200juta.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2020-28458, a Prototype Pollution vulnerability in DataTables versions 1.10.16. The exploit sends a crafted payload to pollute the prototype chain, and a scanner to detect DataTables usage.
Description
All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.
Exploits (2)
This repository contains a functional exploit for CVE-2020-28458, a Prototype Pollution vulnerability in DataTables versions 1.10.16. The exploit sends a crafted payload to pollute the prototype chain, and a scanner to detect DataTables usage.
This repository contains a functional exploit for CVE-2020-28458, a prototype pollution vulnerability in DataTables versions 1.10.16-1.10.16. The exploit sends a crafted JSON payload to pollute the prototype chain, and includes a scanner to detect vulnerable DataTables instances.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L