diff --git a/blog/OVE-20190623-0001.md b/blog/OVE-20190623-0001.md index fd7213b..2817f92 100644 --- a/blog/OVE-20190623-0001.md +++ b/blog/OVE-20190623-0001.md @@ -20,7 +20,7 @@ command injection vulnerability was discovered. This allows for an unauthenticated attacker to execute arbitrary root-level commands on the playground server. -This vulnerability is exploitable instantly by a remote, unauthenticated +This vulnerability is instantly exploitable by a remote, unauthenticated attacker in the default configuration. To remotely exploit this vulnerability, an attacker must send specially created HTTP requests to the playground server containing a malformed function call.