writeups.xyz writeups.xyz / Sivanesh Ashok (@Sivaneshashok)

Title Vulnerabilities Programs Authors
XSS using postMessage in Google Cloud Theia notebooks [Google VRP]
Bypassing authorization in Google Cloud Workstations [Google VRP]
SSH key injection in Google Cloud Compute Engine [Google VRP]
Stealing Google Drive OAuth tokens from Dropbox
Bypassing file upload filter by source code review in Bolt CMS
CSRF to RCE bug chain in Prestashop v1.7.6.4 and below