Assetnote.io Vulnerabilities Writeup
- Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762:
- Citrix Bleed: Leaking Session Tokens with CVE-2023-4966:
- Chaining Three Bugs to Access All Your ServiceNow Data:
- Ivanti’s Pulse Connect Secure Auth Bypass Round Two:
- Digging for SSRF in NextJS apps:
- Advisory: Next.js SSRF (CVE-2024-34351):
- Finding XSS in a million websites (cPanel CVE-2023-29489):
- Why nested deserialization is harmful: Magento XXE (CVE- …:
- RCE in Avaya Aura Device Services:
- RCE in Progress WS_FTP Ad Hoc via IIS HTTP Modules …:
- Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing …:
- Three RCEs and Two Auth Bypasses in Sitecore 9.3:
- Analysis of CVE-2023-3519 in Citrix ADC and NetScaler …:
- Cloudflare Pages, part 1: The fellowship of the secret:
- Exploiting Static Site Generators: When Static Is Not …:
- Advisory: DotCMS Remote Code Execution (CVE-2022- …:
- Research Notes:
- Finding and Exploiting Citrix NetScaler Buffer Overflow …:
- Understanding CVE-2022-22972 (VMWare Workspace …:
- Stealing administrative JWT’s through post auth SSRF …:
- Hacking on Bug Bounties for Four Years:
- Encrypted Doesn’t Mean Authenticated: ShareFile RCE …:
- Cloudflare Pages, part 3: The return of the secrets:
- Turning bad SSRF to good SSRF: Websphere Portal (CVE- …:
- A Glossary of Blind SSRF Chains:
- Diving Deeper into WatchGuard Pre-Auth RCE - CVE-2022 …:
- Hacking a Bank by Finding a 0day in DotCMS:
- Advisory: Sitecore RCE via Insecure Deserialization:
- Sitecore Experience Platform Pre-Auth RCE - CVE-2021- …: