writeups.xyz writeups.xyz / Insecure Deserialization

Title Vulnerabilities Programs Authors
CVE-2020-11518: how I bruteforced my way into your Active Directory
ZombieVPN, Breaking That Internet Security
Universal RCE with Ruby YAML.load
Ruby 2.x Universal RCE Deserialization Gadget Chain
How i found a 1500$ worth Deserialization vulnerability
Adobe ColdFusion Deserialization RCE (CVE-2017-11283, CVE-2017-11284)
How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE!
Type Juggling and PHP Object Injection, and SQLi, Oh My!
Deserialization in Perl v5.8