Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
844Unit 42 Finds Three Vulnerabilities in OpenLiteSpeed Web Server RCE OS command injection Path traversal Local Privilege Escalation LiteSpeed Artur Avetisyan (@3v1LMonk3y) Bug Bounty2022-11-102023-06-13
842Windows Kernel: Exploit CVE-2022-35803 in Common Log File System Windows Local Privilege Escalation Type confusion Microsoft luckyu (@uuulucky) Bug Bounty2022-11-112023-06-13
837CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS MacOS Local Privilege Escalation SIP bypass Apple Mickey Jin (@patch1t) Bug Bounty2022-11-112023-06-13
833CVE-2022-32929 - Bypass iOS backup%27s TCC protection Local Privilege Escalation TCC bypass MacoS iOS Apple Csaba Fitzl (@theevilbit) Bug Bounty2022-11-142023-06-13
831SSD Advisory – Cisco Secure Manager Appliance jwt_api_impl Hardcoded JWT Secret Elevation of Privilege Hardcoded credentials Security code review JWT Privilege escalation Cisco - Bug Bounty2022-11-142023-06-13
815MEGA’s Unlimited Cloud Storage Vulnerability Logic flaw Privilege escalation MEGA Nirmal Dahal (@TheNittam) Bug Bounty2022-11-172023-06-13
810macOS Sandbox Escape vulnerability via Terminal MacOS Sandbox escape Local Privilege Escalation Apple Wojciech Reguła (@_r3ggi) Bug Bounty2022-11-182023-06-13
797A Confused Deputy Vulnerability in AWS AppSync Confused deputy Cloud Privilege escalation AWS Nick Frichette (@frichette_n) Bug Bounty2022-11-212023-06-13
784From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942) Authentication bypass Kerberos RCE Privilege escalation Security code review Intel Julien Ahrens (@MrTuxracer) Bug Bounty2022-11-232023-06-13
761Broken access control + misconfiguration = Beautiful privilege escalation Broken Access Control Privilege escalation NA Hossam Mesbah (@m359ah) Bug Bounty2022-11-282023-06-13
760discord.exe – Improper Input Validation Security code review Local Privilege Escalation Phishing Discord RiotSecTeam (@RiotSecTeam) Bug Bounty2022-11-282023-06-13
756Brocade Fabric OS ≤ v8.0.2c rbash escape to read system files rbash escape Local Privilege Escalation Broadcom Bitcrack (@bitcrack_cyber) Bug Bounty2022-11-292023-06-13
749Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential for unauthorized database access Cloud SQL injection Privilege escalation Information disclosure IBM Ronen Shustin (@ronenshh) Bug Bounty2022-12-012023-06-13
746From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225) SQL injection Kerberos RCE Privilege escalation Security code review Intel Julien Ahrens (@MrTuxracer) Bug Bounty2022-12-012023-06-13
742Multiple Vulnerabilities in Proxmox VE & Proxmox Mail Gateway XSS CRLF injection SSRF LFI Local Privilege Escalation Arbitrary file read Proxmox JianTao Li (@cursered) Bug Bounty2022-12-022023-06-13
741CertPotato – Using ADCS to privesc from virtual and network service accounts to local system Local Privilege Escalation ADCS Microsoft Hocine Mahtout (@Sant0rryu) Bug Bounty2022-12-022023-06-13
738SysmonEoP Local Privilege Escalation Windows Microsoft Filip Dragovic (@filip_dragovic) Bug Bounty2022-12-032023-06-13
715Privilege Escalation to remove the owner from the organization Privilege escalation Mass assignment NA Hemant Kumar Bug Bounty2022-12-092023-06-13
713Public Report – VPN by Google One Security Assessment Android iOS DoS Windows MacoS Local Privilege Escalation Google Daniel Romero (@daniel_rome) Bug Bounty2022-12-092023-06-13
700CVE-2019–6238: Apple XAR directory traversal vulnerability Local Privilege Escalation Apple Yiğit Can Yılmaz Bug Bounty2022-12-132023-06-13
699AWS ECR Public Vulnerability Cloud Privilege escalation Broken Access Control AWS Gafnit Amiga (@gafnitav) Bug Bounty2022-12-132023-06-13
695Privilege escalation leads to deleting other user’s account and company Workspace [Access Control] Privilege escalation Broken Access Control NA Pratik Gaikwad Bug Bounty2022-12-142023-06-13
681Gatekeeper’s Achilles heel: Unearthing a macOS vulnerability Local Privilege Escalation GateKeeper bypass Apple (macOS) Jonathan Bar Or (@yo_yo_yo_jbo) Bug Bounty2022-12-172023-06-13
672Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities MacOS Local Privilege Escalation SIP bypass Apple (macOS) Mickey Jin (@patch1t) Bug Bounty2022-12-202023-06-13
670A Technical Analysis of CVE-2022-22583 and CVE-2022-32800 MacOS Local Privilege Escalation SIP bypass Apple (macOS) Mickey Jin (@patch1t) Bug Bounty2022-12-212023-06-13