How to buy MacBook for $1, or hacking SAP POS

SAP POS Xpress Server does not perform any authentication checks for critical functionality that requires user identity. As a result, administrative and other privileged functions can be accessed without any authentication procedure thus allowing anyone who gets into the network to change prices or set discounts. The vulnerabilities were identified by ERPScan researchers and reported […]