Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
110A deep-dive on Pluck CMS vulnerability CVE-2023-25828 Unrestricted file upload RCE Security code review Pluck CMS Matthew Hogg Bug Bounty2023-05-082023-06-13
109PwnAssistant - Controlling /home%27s Via A Home Assistant RCE Authentication bypass RCE Security code review IoT Home Assistant elttam (@elttam) Bug Bounty2023-05-092023-06-13
104Bypass IIS Authorisation with this One Weird Trick - Three RCEs and Two Auth Bypasses in Sitecore 9.3 RCE Authorization bypass Security code review Sitecore Dylan Pindur Bug Bounty2023-05-102023-06-13
94Pimcore: One click, two security vulnerabilities Path traversal SQL injection Arbitrary file write RCE Security code review Pimcore Yaniv Nizry (@YNizry) Bug Bounty2023-05-152023-06-13
87Unauthenticated Remote Command Execution in Multiple WAGO Products RCE OS command injection Security code review WAGO Quentin Kaiser (@QKaiser) Bug Bounty2023-05-162023-06-13
86Hardcore RCE via directory name for $3.000 RCE OS command injection Security code review NA Lev Shmelev Bug Bounty2023-05-162023-06-13
34RCE via LDAP truncation on hg.mozilla.org RCE LDAP truncation Security code review Mozilla joernchen (@joernchen) Bug Bounty2023-06-032023-06-13
26Storing Passwords - A Journey Of Common Pitfalls Pass-the-Hash Authentication flaw Security code review STARFACE RedTeam Pentesting (@RedTeamPT) Bug Bounty2023-06-052023-06-13
22SSD Advisory – Roundcube MarkAsJunk RCE RCE OS command injection Security code review Roundcube Selim Enes Karaduman (@Enesdex) Bug Bounty2023-06-062023-06-13