Posts on web-security
5 posts tagged web-security.
-
CVE-2019-9194: elFinder Command Injection 1-Day Exploit
CVE-2019-9194 elFinderAnalysis and exploitation of CVE-2019-9194, a command injection vulnerability in elFinder, from discovery to functional exploit development.
6 min read rceweb-securityexploit-development -
CVE-2019-9960: LimeSurvey Arbitrary File Download
CVE-2019-9960 LimeSurveyAnalysis of CVE-2019-9960, arbitrary file download vulnerability in LimeSurvey through Directory Traversal exploitation.
7 min read path-traversalweb-security -
CVE-2019-14670 - LimeSurvey TCPDF RCE via PHAR File
CVE-2019-14670 LimeSurveyRemote code execution in LimeSurvey < 3.17 through TCPDF PHAR deserialization attack, exploiting queXML PDF export functionality.
4 min read rceweb-securityexploit-development -
CVE-2019-3809: Moodle Blind SSRF Vulnerability Analysis
CVE-2019-3809 MoodleAnalysis of a Blind Server-Side Request Forgery vulnerability in Moodle's badge backpack functionality allowing internal network reconnaissance.
4 min read ssrfweb-securityvulnerability-research -
License Plate OSINT: Argentina Vehicle Registry
How I reverse-engineered Argentina's license plate system to track down a hit-and-run driver using client-side JavaScript vulnerabilities.
8 min read osintweb-securityreverse-engineering