Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4720Manage Engine OpManager Multiple Authenticated RCE Vulnerabilities RCE Path traversal Unrestricted file upload Information disclosure Arbitrary file write Zoho (ManageEngine) Denis Andzakovic Bug Bounty2018-06-182023-06-13
3020OpenEMR 5.0.1.3 Arbitrary File Actions Arbitrary file write Arbitrary file read Security code review OpenEMR Josh Fam (@Pullerze) Bug Bounty2020-11-172023-06-13
3015Arbitrary File Write On Client By ADB Pull Arbitrary file write Google Serafina (Sera) Tonin Brocious (@daeken) Bug Bounty2020-11-192023-06-13
3007SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover RCE SSRF Arbitrary file write Path traversal OS command injection Local Privilege Escalation Cisco Realmode Labs (@RealmodeLabs) Bug Bounty2020-11-232023-06-13
2490Two weeks of securing Samsung devices: Part 1 Arbitrary file write Insecure intent Android Samsung Oversecured (@OversecuredInc) Bug Bounty2021-06-102023-06-13
2472Why dynamic code loading could be dangerous for your apps: a Google example Arbitrary file write Insecure intent Android Google Oversecured (@OversecuredInc) Bug Bounty2021-06-172023-06-13
2318Two weeks of securing Samsung devices: Part 2 Arbitrary file write Arbitrary file read Vulnerable Android content provider Android Samsung Oversecured (@OversecuredInc) Bug Bounty2021-08-162023-06-13
2116Apple XAR – Arbitrary File Write (CVE-2021-30833) Arbitrary file write Apple Richard Warren (@buffaloverflow) Bug Bounty2021-10-282023-06-13
1806Analyzing a PJL directory traversal vulnerability – exploiting the Lexmark MC3224i printer (part 2) Arbitrary file write Race condition Printer hacking Lexmark Cedric Halbronn (@saidelike) Bug Bounty2022-02-182023-06-13
1788CVE-2021-45467: CWP CentOS Web Panel – preauth RCE RCE LFI Arbitrary file write Centos Web Panel (CWP) Paulos Yibelo (@PaulosYibelo) Bug Bounty2022-01-222023-06-13
1728Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582) Arbitrary file write Apple Richard Warren (@buffaloverflow) Bug Bounty2022-03-152023-06-13
1417Unrar Path Traversal Vulnerability affects Zimbra Mail Path traversal Arbitrary file write RCE Zimbra Sonar (@SonarSource) Bug Bounty2022-06-282023-06-13
1284(ZOHO) Manage Engine Desktop Central – SQL Injection / Arbitrary File Write SQL injection Arbitrary file write Path traversal Zoho Tom Ellson (@tde_sec) Bug Bounty2022-08-022023-06-13
1152CVE-2022-26113: FortiClient Arbitrary File Write As SYSTEM Arbitrary file write Local Privilege Escalation Fortinet David Yesland (@daveysec) Bug Bounty2022-08-302023-06-13
1100Riding The Inforail To Exploit Ivanti Avalanche Part 2 RCE Insecure deserialization Path traversal Authentication bypass Unrestricted file upload Arbitrary file write Arbitrary file read Ivanti Piotr Bazydło (@chudyPB) Bug Bounty2021-09-082023-06-13
1046Exploiting Distroless Images Command injection Arbitrary file read Arbitrary file write Container escape Google Daniel Teixeira (@TheRedOperator) Bug Bounty2022-09-222023-06-13
972Pwning ManageEngine — From Endpoint to Exploit: A deep dive into CVE-2021–42847 Arbitrary file write XXE RCE Zoho Erik Wynter (@WynterErik) Bug Bounty2022-10-122023-06-13
950Toner Deaf – Printing your next persistence (Hexacon 2022) Path traversal Arbitrary file write RCE Printer hacking Lexmark Alex Plaskett (@alexjplaskett) Bug Bounty2022-10-172023-06-13
93023000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite JWT Authentication bypass Arbitrary file write Unrestricted file upload NA Souhaib Naceri (@h4x0r_dz) Bug Bounty2022-10-192023-06-13
693CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution Websockets RCE Arbitrary file write Path traversal OnlyOffice Iain Wallace (@strawp) Bug Bounty2022-12-142023-06-13
691CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution Websockets XSS RCE Arbitrary file write Path traversal OnlyOffice Iain Wallace (@strawp) Bug Bounty2022-12-142023-06-13
609Uploading the Webshell using filename of Content-Disposition Header Story! Unrestricted file upload Arbitrary file write NA Yashar Mohagheghi Bug Bounty2023-01-092023-06-13
532Froxlor v2.0.6 Remote Command Execution (CVE-2023-0315) RCE Arbitrary file write SSTI Security code review Froxlor Askar (@mohammadaskar2) Bug Bounty2023-01-292023-06-13
440EoP via Arbitrary File Write/Overwite in Group Policy Client “gpsvc” – CVE-2022-37955 Local Privilege Escalation Microsoft (Windows) ap (@decoder_it) Bug Bounty2023-02-162023-06-13
376A New Vector For “Dirty” Arbitrary File Write to RCE Arbitrary file write RCE NA Maxence Schmitt (@maxenceschmitt) Bug Bounty2023-02-282023-06-13