Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3657A Tale of Two Formats: Exploiting Insecure XML and ZIP File Parsers to Create a Web Shell XXE RCE Directory Traversal NA Eugene Lim (@spaceraccoonsec) Bug Bounty2020-02-182023-06-13
3217Open Sesame: Escalating Open Redirect to RCE with Electron Code Review Open redirect RCE Security code review NA Eugene Lim (@spaceraccoonsec) Bug Bounty2020-08-142023-06-13
2950Supply Chain Pollution: Hunting a 16 Million Download/Week npm Package Vulnerability for a CTF Challenge Prototype pollution Node.js third-party modules Eugene Lim (@spaceraccoonsec) Bug Bounty2020-12-232023-06-13
2843Applying Offensive Reverse Engineering to Facebook Gameroom Insecure deserialization Meta / Facebook Eugene Lim (@spaceraccoonsec) Bug Bounty2021-02-022023-06-13
2214All Your (d)Base Are Belong To Us, Part 1: Code Execution in Apache OpenOffice (CVE-2021–33035) RCE Memory corruption Apache Eugene Lim (@spaceraccoonsec) Bug Bounty2021-09-172023-06-13
2134All Your (d)Base Are Belong To Us, Part 2: Code Execution in Microsoft Office (CVE-2021-38646) RCE Memory corruption Microsoft Eugene Lim (@spaceraccoonsec) Bug Bounty2021-10-222023-06-13
1854Solving DOM XSS Puzzles DOM XSS NA Eugene Lim (@spaceraccoonsec) Bug Bounty2022-02-032023-06-13
1207You Have One New Appwntment: Exploiting iCalendar Properties in Enterprise Applications XSS SMTP injection VMware Synology Apple Microsoft Google NextCloud Eugene Lim (@spaceraccoonsec) Bug Bounty2022-08-182023-06-13
1158Exploiting Improper Validation of Amazon Simple Notification Service SigningCertUrl Authorization flaw Signature validation bypass Amazon Eugene Lim (@spaceraccoonsec) Bug Bounty2022-08-302023-06-13
682I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS Stored XSS Self-XSS Zoom Eugene Lim (@spaceraccoonsec) Bug Bounty2022-12-172023-06-13