107 подписчиков
12 видео
Reflected XSS via REQUEST_URI & Internet Explorer
last pass XSS when sharing folder - Marked as [NOT APLICABLE] zero day
Osticket v1.9.14 and below (X-Forwarded-For) - Stored XSS (PoC)
Moodle 3.1.2 - Installation process SQLi
Wordpress Ultimate Product Catalog v3.8.6 - Arbitrary file upload (RCE)
Wordpress Ultimate Product Catalog v3.8.1 and below - Privilege escalation [IDOR]
CP polls executable download (PoC)
Cp calculated fields form - Http only bypass & session hijacking (PoC)
Telmex Hub - CSRF && XSS - Session hijacking vulnerability (Fixed)
Telmex Hub SQL injection vulnerability
dwbooster.com (codepeople plugins & extensions) 2015 SQLi vulnerability
HUGE IT SLIDER 2.7.5 CSRF & Persistent JS HTML code injection, Arbitrary slider deletion (PoC)