Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
3881
Finding SQL injections fast with white-box analysis — a recent bug example
SQL injection
Zoho
Florian Hauser (@frycos)
Bug Bounty
2019-10-13
2023-06-13
3489
Another Zoho ManageEngine Story
Authentication bypass
Zoho
Florian Hauser (@frycos)
Bug Bounty
2020-05-11
2023-06-13
1922
Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
Insecure deserialization
Microsoft
Florian Hauser (@frycos)
Bug Bounty
2022-01-13
2023-06-13
1047
Skype for Business Audit Part 1 - SKYPErsistence
Local Privilege Escalation
Windows
Security code review
Microsoft
Florian Hauser (@frycos)
Bug Bounty
2022-09-22
2023-06-13
1030
Skype for Business Audit Part 2 - SKYPErimeterleak
SSRF
Security code review
Microsoft
Florian Hauser (@frycos)
Bug Bounty
2022-09-26
2023-06-13
740
Pre-Auth RCE with CodeQL in Under 20 Minutes
Security code review
RCE
Command injection
Authorization flaw
pgAdmin
Florian Hauser (@frycos)
Bug Bounty
2022-12-02
2023-06-13
549
Using 0days to Protect the United Nations
RCE
Authentication bypass
Path traversal
United Nations
Florian Hauser (@frycos)
Bug Bounty
2023-01-24
2023-06-13
493
GoAnywhere MFT - A Forgotten Bug
Insecure deserialization
Security code review
Fortra (GoAnywhere)
Florian Hauser (@frycos)
Bug Bounty
2023-02-06
2023-06-13
463
XXE with Auto-Update in install4j
XXE
Security code review
Prosys OPC
Florian Hauser (@frycos)
Bug Bounty
2023-02-12
2023-06-13
206
Java Exploitation Restrictions in Modern JDK Times
Insecure deserialization
NA
Florian Hauser (@frycos)
Bug Bounty
2023-04-11
2023-06-13