Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5107Type Juggling and PHP Object Injection, and SQLi, Oh My! Type juggling PHP Object Injection Insecure deserialization SQL injection NA Justin Kennedy (@jstnkndy) Bug Bounty2017-02-072023-06-13
5015How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! SSRF RCE CRLF injection Insecure deserialization GitHub Orange Tsai (@orange_8361) Bug Bounty2017-07-282023-06-13
4621How i found a 1500$ worth Deserialization vulnerability Misconfigured JSF ViewState Insecure deserialization NA Ashish Kunwar (@D0rkerDevil) Bug Bounty2018-08-282023-06-13
3351ZombieVPN, Breaking That Internet Security RCE Insecure deserialization Bitdefender AnchorFree 0xSha (@0xsha) Bug Bounty2020-07-012023-06-13
2901GoCD Multiple Vulnerabilities RCE Information disclosure Insecure deserialization Security code review GoCD Denis Andzakovic Bug Bounty2021-01-122023-06-13
2843Applying Offensive Reverse Engineering to Facebook Gameroom Insecure deserialization Meta / Facebook Eugene Lim (@spaceraccoonsec) Bug Bounty2021-02-022023-06-13
2712CVE-2021-27076: A Replay-style Deserialization Attack Against Sharepoint Insecure deserialization RCE Microsoft Simon Zuckerbraun (@HexKitchen) Bug Bounty2021-03-172023-06-13
2664Remote code execution through unsafe unserialize in PHP Insecure deserialization RCE NA Sjoerd Langkemper Bug Bounty2021-04-042023-06-13
2586Basic recon to RCE Insecure deserialization RCE NA Joshua Martinelle (@J0_mart) Bug Bounty2021-05-022023-06-13
2437Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464) RCE Insecure deserialization NA Michael Stepankin (@artsploit) Bug Bounty2021-06-292023-06-13
2351Detecting Jackson deserialization vulnerabilities with CodeQL Insecure deserialization GitHub Artem Smotrakov (@artem_smotrakov) Bug Bounty2021-08-022023-06-13
2297The Nomulus rift Insecure deserialization Google Imre Rad (@ImreRad) Bug Bounty2021-08-252023-06-13
2140Shells And SOAP: Websphere Deserialization To RCE RCE Insecure deserialization IBM Wyatt Dahlenburg (@wdahlenb) Bug Bounty2021-10-182023-06-13
2106Sitecore Experience Platform Pre-Auth RCE - CVE-2021-42237 RCE Insecure deserialization Security code review Sitecore Shubham Shah (@infosec_au) Bug Bounty2021-11-012023-06-13
2073Diving into Open-source LMS Codebases Insecure file upload Insecure deserialization RCE CSRF SQL injection Reflected XSS Moodle Chamilo LMS Poh Jia Hao (@Chocologicall) Bug Bounty2021-11-162023-06-13
1922Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969) Insecure deserialization Microsoft Florian Hauser (@frycos) Bug Bounty2022-01-132023-06-13
1907Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1 Insecure deserialization Cryptographic issues Swiss Post Ruben Santamarta (@reversemode) Bug Bounty2022-01-182023-06-13
1884The Story of an RCE on a Java Web Application Insecure deserialization NA LIL NIX (@Lil__Nix) Bug Bounty2022-01-272023-06-13
1882The Story of a RCE on a Java Web Application RCE Insecure deserialization NA LIL NIX (@Lil__Nix) Bug Bounty2022-01-282023-06-13
1855HigherLogic Community RCE Vulnerability Insecure deserialization RCE 8x8 IBM 0daystolive (@0daystolive) Bug Bounty2022-02-032023-06-13
1690Ruby Deserialization - Gadget on Rails Insecure deserialization RCE Ruby on Rails HTTPVoid (@httpvoid0x2f) Bug Bounty2022-03-282023-06-13
1683Unauthenticated Remote Code Execution in Cisco Nexus Dashboard Fabric Controller (formerly DCNM) Insecure deserialization Local Privilege Escalation RCE Cisco Pedro Ribeiro (@pedrib1337) Bug Bounty2022-03-302023-06-13
1622CVE-2022-26133 - Bitbucket Data Center - Java Deserialization Vulnerability Insecure deserialization Atlassian Benny Jacob (@bennyyjacob) Bug Bounty2022-04-142023-06-13
1557New Wine in Old Bottle - Microsoft Sharepoint Post-Auth Deserialization RCE (CVE-2022-29108) Insecure deserialization RCE Microsoft Nguyễn Tiến Giang (@testanull) Bug Bounty2022-05-122023-06-13
1543CVE-2022-21404: Another Story Of Developers Fixing Vulnerabilities Unknowingly Because Of CodeQL Insecure deserialization Oracle Paulino Calderon (@calderpwn) Bug Bounty2022-05-192023-06-13