writeups.xyz writeups.xyz / Insecure Deserialization

Title Vulnerabilities Programs Authors
Attacking PowerShell CLIXML Deserialization
Getting code execution on Veeam through CVE-2023-27532
3 ways to get Remote Code Execution in Kafka UI
Dynamics 365 Business Central - A Journey With Ups and Downs
Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve) (CVSS 9.9, CVSS 9.8) Walkthrough
Why nested deserialization is harmful: Magento XXE (CVE-2024-34102)
Molding Lies Into Reality || Exploiting CVE-2024-4358
My LLM Bug Bounty Journey on Hugging Face Hub via Protect AI
R-bitrary Code Execution: Vulnerability In R’s Deserialization (CVE-2024-27322)
Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations
Apache Dubbo Consumer Risks: The Road Not Taken
Java Deserialization Tricks
Discovering Deserialization Gadget Chains in Rubyland
Continuing the Citrix Saga: CVE-2023-5914 & CVE-2023-6184
Nom for Security: A Proactive Security Review of Nomulus
Hello Lucee! Let us hack Apple again?
PHP deserialization attacks and a new gadget chain in Laravel
Java applet + serialization in 2024! What could go wrong?
Relution Remote Code Execution via Java Deserialization Vulnerability
Multiple vulnerabilities in Cisco Unified Communications Manager version 11.5.1
Gambio 4.9.2.0 - Insecure Deserialization
CVE-2023–50220 — Inductive Automation Ignition XML Deserialization to RCE
Unauthenticated RCE in Adobe Coldfusion – CVE-2023-26360
Panic!! At the YAML
DoubleTrouble