Writeups
Spotlight
Add Your Writeup
Blogs
Contact Us
Register
Login
Write-ups
Check The Published Writeups
Search
Reset
WDB
Title
Tags
Programs
Authors
Type
Publication
Added
1338
Riding The Inforail To Exploit Ivanti Avalanche
RCE
Insecure deserialization
Race condition
Authentication bypass
Ivanti
Piotr Bazydło (@chudyPB)
Bug Bounty
2022-07-19
2023-06-13
1100
Riding The Inforail To Exploit Ivanti Avalanche Part 2
RCE
Insecure deserialization
Path traversal
Authentication bypass
Unrestricted file upload
Arbitrary file write
Arbitrary file read
Ivanti
Piotr Bazydło (@chudyPB)
Bug Bounty
2021-09-08
2023-06-13
884
Vulnerabilities In Apache Batik Default Security Controls – SSRF And RCE Through Remote Class Loading
SSRF
RCE
Apache Batik
Piotr Bazydło (@chudypb)
Bug Bounty
2022-10-31
2023-06-13
823
Control Your Types Or Get Pwned: Remote Code Execution In Exchange Powershell Backend
RCE
Windows
Checkmk
Piotr Bazydło (@chudyPB)
Bug Bounty
2022-11-16
2023-06-13
479
Pwn2Owning Two Hosts At The Same Time: Abusing Inductive Automation Ignition’s Custom Deserialization
Insecure deserialization
RCE
Security code review
Inductive Automation Ignition
Piotr Bazydło (@chudyPB)
Bug Bounty
2023-02-08
2023-06-13
378
CVE-2022-38108: RCE In Solarwinds Network Performance Monitor
Insecure deserialization
RCE
Security code review
SolarWinds
Piotr Bazydło (@chudyPB)
Bug Bounty
2023-02-28
2023-06-13