Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4922SQL Injection in rog.asus.com SQL injection Security code review Asus Corben Leo (@hacker_) Bug Bounty2017-11-302023-06-13
3668CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE RCE Stored XSS CSP bypass Arbitrary file read Open redirect Security code review Meta / Facebook (WhatsApp) Gal Weizman (@WeizmanGal) Bug Bounty2020-02-142023-06-13
3492Pentesting Cisco SD-WAN Part 2: Breaking Routers OS command injection Security code review Cisco Julien Legras (@Julien_Legras) Bug Bounty2020-05-072023-06-13
3442Analysis and Discovery of CVE-2020-13693 Privilege escalation Security code review BBPress Raphael Karger (@pwnszn) Bug Bounty2020-05-292023-06-13
3362Bypassing file upload filter by source code review in Bolt CMS RCE Unrestricted file upload Path traversal Security code review Bolt CMS Sivanesh Ashok (@sivaneshashok) Bug Bounty2020-06-272023-06-13
3217Open Sesame: Escalating Open Redirect to RCE with Electron Code Review Open redirect RCE Security code review NA Eugene Lim (@spaceraccoonsec) Bug Bounty2020-08-142023-06-13
3071Weblogic RCE by only one GET request — CVE-2020–14882 Analysis RCE Authentication bypass Security code review Oracle (WebLogic) Nguyễn Tiến Giang (@testanull) Bug Bounty2020-10-282023-06-13
3020OpenEMR 5.0.1.3 Arbitrary File Actions Arbitrary file write Arbitrary file read Security code review OpenEMR Josh Fam (@Pullerze) Bug Bounty2020-11-172023-06-13
2901GoCD Multiple Vulnerabilities RCE Information disclosure Insecure deserialization Security code review GoCD Denis Andzakovic Bug Bounty2021-01-122023-06-13
2596PHP Supply Chain Attack on Composer Argument injection RCE Supply chain attack Security code review Packagist Thomas Chauchefoin (@swapgs) Bug Bounty2021-04-292023-06-13
253713 Nagios Vulnerabilities, #7 will SHOCK you! RCE Local Privilege Escalation XSS Security code review Nagios Samir Ghanem (@sam0x21r) Bug Bounty2021-05-202023-06-13
2495Joomla Password Reset Vulnerability And A Stored XSS For Full Compromise Password reset Stored XSS Privilege escalation RCE Security code review NA Adrian Tiron (@Adrian__T) Bug Bounty2021-06-072023-06-13
2171CVE-2021-43136 – FormaLMS – The evil default value that leads to Authentication Bypass Authentication bypass Security code review Forma LMS Cristian Giustini Bug Bounty2021-10-052023-06-13
2142Independently Secure, Together Not So Much – A Story Of 2 WP Plugins RCE Race condition Unrestricted file upload Security code review NA Adrian Tiron (@Adrian__T) Bug Bounty2021-10-172023-06-13
2106Sitecore Experience Platform Pre-Auth RCE - CVE-2021-42237 RCE Insecure deserialization Security code review Sitecore Shubham Shah (@infosec_au) Bug Bounty2021-11-012023-06-13
1810CVE-2022-0478 - WooCommerce Event-Manager Plugin SQL Injection SQL injection Security code review Automattic (WooCommerce) Castilho (@castilho101) Bug Bounty2022-02-162023-06-13
1596[EN] Privileged account creation via Mass Assignment towards a full compromise using a Stored XSS Stored XSS Mass assignment Security code review pass Culture Aethlios (@AethliosIK) Bug Bounty2022-04-262023-06-13
1517DNN CMS Server-Side Request Forgery (CVE-2021-40186) SSRF Security code review DNN (DotNetNuke) Appcheck NG Bug Bounty2022-05-262023-06-13
1047Skype for Business Audit Part 1 - SKYPErsistence Local Privilege Escalation Windows Security code review Microsoft Florian Hauser (@frycos) Bug Bounty2022-09-222023-06-13
1030Skype for Business Audit Part 2 - SKYPErimeterleak SSRF Security code review Microsoft Florian Hauser (@frycos) Bug Bounty2022-09-262023-06-13
1002Securing Developer Tools: A New Supply Chain Attack on PHP Argument injection RCE Supply chain attack Security code review Packagist Thomas Chauchefoin (@swapgs) Bug Bounty2022-10-042023-06-13
981VMware vCenter Server Platform Services Controller Unsafe Deserialization vulnerability Insecure deserialization Security code review VMware Marcin %27Icewall%27 Noga (@_Icewall) Bug Bounty2022-10-102023-06-13
959Weak private key generation in SSH.NET <= 2020.0.1 Weak crypto Security code review SSH.NET Guillaume André (@yaumn_) Bug Bounty2022-10-142023-06-13
958Code Injection and SQLi in WP ALL Export Pro SQL injection Security code review NA p3n7a90n (@p3n7a90n) Bug Bounty2022-10-142023-06-13
941Remote Code Execution in Melis Platform RCE Path traversal Insecure deserialization Security code review Melis Platform Karim El Ouerghemmi Bug Bounty2022-10-182023-06-13