BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//conference.c3w.at//bsv19//AG9NKZ
BEGIN:VTIMEZONE
TZID:Europe/Vienna
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsv19-C8S7CE@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20191130T111000
DTEND;TZID=Europe/Vienna:20191130T115500
DESCRIPTION:PHP Object Injection is a well known web vulnerability that cou
 ld allow an attacker to perform different kinds of attacks by reusing and 
 chaining existing code of the application(gadgets). Sometimes it is easier
  to find the vulnerability than discovering a proper chain for a remote co
 de execution. This talk illustrates the long road of searching for various
  "POP chains" by disclosing details of a vulnerability for Okay-CMS. The c
 ode of the application will be analyzed and possible payloads will be disc
 ussed. A working unauthenticated remote code execution exploit will finall
 y proof the concept.
DTSTAMP:20260908T061549Z
LOCATION:Dachsaal
SUMMARY:Code diving for pop chains - Wolfgang Hotwagner
URL:https://cfp.bsidesvienna.at/bsv19/talk/C8S7CE/
END:VEVENT
END:VCALENDAR
