writeups.xyz writeups.xyz / William Bowling / Vakzz (@Wcbowling)

Title Vulnerabilities Programs Authors
ExifTool CVE-2021-22204 - Arbitrary Code Execution
Universal Deserialisation Gadget for Ruby 2.x-3.x
GitHub Pages - Multiple RCEs via insecure Kramdown configuration - $25,000 Bounty
GitHub Gist - Account takeover via open redirect - $10,000 Bounty
GitHub - RCE via git option injection (almost) - $20,000 Bounty