writeups.xyz writeups.xyz / Adam Kues (@Hash_kitten)

Title Vulnerabilities Programs Authors
Chaining Three Bugs to Access All Your ServiceNow Data
Why nested deserialization is harmful: Magento XXE (CVE-2024-34102)
Digging for SSRF in NextJS apps
Continuing the Citrix Saga: CVE-2023-5914 & CVE-2023-6184
Leaking File Contents with a Blind File Oracle in Flarum