writeups.xyz writeups.xyz / LFI

Title Vulnerabilities Programs Authors
How I found multiple critical bugs in Red Bull
Multiple Vulnerabilities in Proxmox VE & Proxmox Mail Gateway
Bypassing The Client Side Encryption To Read Internal Windows Server Files
From Shodan Dork to Grafana 📊Local File Inclusion
CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities
Critical Local File Read in Electron Desktop App
Local File Inclusion (interesting method)
Advisory | GLPI Service Management Software Multiple Vulnerabilities and Remote Code Execution
From open redirect to RCE in one week
Research: Auditing WordPress Plugins
AWS RDS Vulnerability Leads to AWS Internal Service Credentials
Pwning a Server using Markdown
SSRF & LFI In Uploads Feature
Path Traversal Paradise
CVE-2021-45467: CWP CentOS Web Panel – preauth RCE
120 Days of Frequent Hacking
120 Days of High Frequency Hunting
VMware vCenter earlier versions (7.0.2.00100) has unauthorized arbitrary file read + ssrf + xss vulnerability
Exploiting HTML-to-PDF Converters through HTML Imports
SSRF in PDF export with PhantomJs
Escalating XSS to Arbitrary File Read
Bypassing LFI (Local File Inclusion)
CVE-2020-35580
PHP fopen() function to local file inclusion
How i got my First Bug Bounty in Intersting Target (LFI to SXSS)