writeups.xyz writeups.xyz / Insecure Deserialization

Title Vulnerabilities Programs Authors
Gadgets chain in Laravel
Securing our home labs: Home Assistant code review
Gadgets chain in WordPress
Finding A RCE Gadget Chain In WordPress Core
Finding A Pop Chain On A Common Symfony Bundle: Part 2
RCE in Progress WS_FTP Ad Hoc via IIS HTTP Modules (CVE-2023-40044)
Finding Deserialization Bugs In The Solarwind Platform
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
Finding A Pop Chain On A Common Symfony Bundle: Part 1
Paranoids Vulnerability Research: Ivanti Issues Security Alert
Apache Superset Part II: RCE, Credential Harvesting and More
Part 3: Learning iOS App Pentesting and Application Security with Real-World Case Studies
Identifying and Exploiting Unsafe Deserialization in Ruby
Adobe ColdFusion Pre-Auth RCE(s)
Exploiting JMeter via RMI
From Blackbox .NET Remoting to Unauthenticated Remote Code Execution
CVE-2023-20864: Remote Code Execution In VMware Aria Operations For Logs
FortiNAC - Just a few more RCEs
Jasper Reports Library Code Injection
Multiple vulnerabilities in Delmia Apriso 2017 to 2022
Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707)
Weblogic CVE-2023-21931 vulnerability exploration technique: post-deserialization exploitation
Java Exploitation Restrictions in Modern JDK Times
Riding the Azure Service Bus (Relay) into Power Platform
Feeding Tasty Objects to Visual Studio's App Center SDK for Apple