2024-07-22 |
JNDI Injection Remote Code Execution via Path Manipulation in MemoryUserDatabaseFactory |
blog |
|
2022-10-26 |
Eat What You Kill :: Pre-authenticated Remote Code Execution in VMWare NSX Manager |
blog |
|
2022-08-12 |
IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit |
blog |
|
2022-08-10 |
From Shared Dash to Root Bash :: Pre-Authenticated RCE in VMWare vRealize Operations Manager |
blog |
|
2022-01-22 |
ZohOwned :: A Critical Authentication Bypass on Zoho ManageEngine Desktop Central |
blog |
|
2021-11-23 |
Unlocking the Vault :: Unauthenticated Remote Code Execution against CommVault Command Center |
blog |
|
2021-09-30 |
Chasing a Dream :: Pre-authenticated Remote Code Execution in Dedecms |
blog |
|
2021-08-25 |
Pwn2Own Vancouver 2021 :: Microsoft Exchange Server Remote Code Execution |
blog |
|
2021-07-13 |
Full Stack Web Attack 2021 :: Zero Day Give Away |
blog |
|
2021-02-28 |
Busting Cisco's Beans :: Hardcoding Your Way to Hell |
blog |
|
2021-02-28 |
Smarty Template Engine Multiple Sandbox Escape PHP Code Injection Vulnerabilities |
blog |
|
2021-02-28 |
A SmorgasHORDE of Vulnerabilities :: A Comparative Analysis of Discovery |
blog |
|
2021-02-28 |
SharePoint and Pwn :: Remote Code Execution Against SharePoint Server Abusing DataSet |
blog |
|
2021-02-28 |
SQL Injection Double Uppercut :: How to Achieve Remote Code Execution Against PostgreSQL |
blog |
|
2021-02-28 |
Strike Three :: Symlinking Your Way to Unauthenticated Access Against Cisco UCS Director |
blog |
|
2021-02-28 |
Silent Schneider :: Revealing a Hidden Patch in EcoStruxure Operator Terminal Expert |
blog |
|
2021-02-28 |
Attacking Unmarshallers :: JNDI Injection using Getter Based Deserialization Gadgets |
blog |
|
2021-02-28 |
Panic! at the Cisco :: Unauthenticated Remote Code Execution in Cisco Prime Infrastructure |
blog |
|
2021-02-28 |
Making Clouds Rain :: Remote Code Execution in Microsoft Office 365 |
blog |
|