writeups.xyz writeups.xyz / Mahmoud Gamal (@Zombiehelp54)

Title Vulnerabilities Programs Authors
Exploits Explained: Permission misconfiguration within Salesforce JavaScript Remoting tokens used for Apex Controllers
SQL Injection: Utilizing XML Functions in Oracle and PostgreSQL to bypass WAFs
Weblogic Remote Code Execution (Exploiting CVE-2019-2725)
Exploiting Out Of Band XXE using internal network and php wrappers
Handlebars template injection and RCE in a Shopify app
SQL Injection and A silly WAF
Let’s steal some tokens!
SQL injection in an UPDATE query - a bug bounty story!
XSS vulnerability in Google image search