At first glance this seems kind of scary, but if it relies on already-reported CVEs, then doesn't that defeat the purpose of using it to breach a vulnerability? AFAIK, CVEs are only disclosed publicly after they've been patched. I could be wrong though.
3 comments
[ 2.8 ms ] story [ 20.4 ms ] thread