Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1012How Scanning Your Projects for Security Issues Can Lead to Remote Code Execution RCE OS command injection Snyk Ron Masas (@RonMasas) Bug Bounty2022-09-292023-06-13
943Basic recon to RCE III RCE OS command injection NA Joshua Martinelle (@J0_mart) Bug Bounty2022-10-182023-06-13
939Vulnerabilities in Tenda%27s W15Ev2 AC1200 Router OS command injection Buffer Overflow Memory corruption Stored XSS Authorization flaw Information disclosure Tenda Olivier Laflamme (@olivier_boschko) Bug Bounty2022-10-192023-06-13
906GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown OS command injection Arbitrary file read Information disclosure Account takeover Stored XSS Lack of rate limiting Weak credentials Password policy bypass GL.iNet Olivier Laflamme (@olivier_boschko) Bug Bounty2022-10-262023-06-13
844Unit 42 Finds Three Vulnerabilities in OpenLiteSpeed Web Server RCE OS command injection Path traversal Local Privilege Escalation LiteSpeed Artur Avetisyan (@3v1LMonk3y) Bug Bounty2022-11-102023-06-13
781Legally hacking a Government Satellite? Missing authentication OS command injection RCE NA RiotSecTeam (@RiotSecTeam) Bug Bounty2022-11-242023-06-13
779CVE-2022–43781 OS command injection RCE Atlassian Petrus Viet (@VietPetrus) Bug Bounty2022-11-252023-06-13
770A Real World Example Of Classic Remote Command Execution (RCE) OS command injection XSS RCE NA Bhashit Pandya (@x30r_) Bug Bounty2022-11-262023-06-13
745Command Injection in Asus M25 NAS OS command injection Source code disclosure Asus Quentin Kaiser (@QKaiser) Bug Bounty2022-12-012023-06-13
740Pre-Auth RCE with CodeQL in Under 20 Minutes Security code review RCE Command injection Authorization flaw pgAdmin Florian Hauser (@frycos) Bug Bounty2022-12-022023-06-13
724The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022 Command injection RCE Security code review Netgear Vu Thi Lan (@lanleft_) Bug Bounty2022-12-062023-06-13
714The first step to PWN2OWN - A sad one Command injection Netgear Vương Quốc Huy Bug Bounty2022-12-092023-06-13
660Puckungfu: A NETGEAR WAN Command Injection OS command injection Security code review Netgear McCaulay Hudson (@_mccaulay) Bug Bounty2022-12-222023-06-13
620Cacti: Unauthenticated Remote Code Execution RCE Authentication bypass OS command injection Security code review Cacti Stefan Schiller (@scryh_) Bug Bounty2023-01-032023-06-13
596SSH key injection in Google Cloud Compute Engine [Google VRP] OS command injection RCE Google Sivanesh Ashok (@sivaneshashok) Bug Bounty2023-01-122023-06-13
560Vulnerabilities in ManageEngine ADSelfService Plus 6.1 build 6117 RCE OS command injection Broken Access Control Zoho (ManageEngine) Antoine Cervoise (@acervoise) Bug Bounty2023-01-202023-06-13
542Kamailio’s exec module considered harmful OS command injection SIP Kamailio Ali Norouzi Bug Bounty2023-01-262023-06-13
437Facebook bug: A Journey from Code Execution to S3 Data Leak RCE OS command injection Meta / Facebook Bipin Jitiya (@win3zz) Bug Bounty2023-02-162023-06-13
407LogicalDOC Vulnerability Disclosure XXE RCE Command injection Privilege escalation LogicalDOC Brett DeWall (@xbadbiddyx) Bug Bounty2023-02-232023-06-13
390The Tale of a Command Injection by Changing the Logo RCE OS command injection Unrestricted file upload Directory listing HTTP response manipulation NA 0xrz (@omidxrz) Bug Bounty2023-02-262023-06-13
385$10.000 bounty for exposed .git to RCE .git folder disclosure RCE OS command injection NA Lev Shmelev Bug Bounty2023-02-272023-06-13
359CS-Cart PDF Plugin Unauthenticated Command Injection RCE OS command injection Security code review CS-Cart Ngo Wei Lin (@Creastery) Bug Bounty2023-03-032023-06-13
332PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749 RCE OS command injection Security code review Netgear Zion Basque (@mahal0z) Bug Bounty2023-03-082023-06-13
328The Silent Spy Among Us: Modern Attacks Against Smart Intercoms IoT OS command injection Missing authentication MiTM SIP Akuvox Claroty%27s Team82 (@Claroty) Bug Bounty2023-03-092023-06-13
314The story of how I was able to chain SSRF with Command Injection Vulnerability SSRF OS command injection RCE NA Raj Qureshi (@RajQureshi9) Bug Bounty2023-03-122023-06-13