r0 ~
16 POSTS · TAG · #php
DATE CAT TITLE
2022 · 3
15-02 EXPLOIT CVE-2022-24977 - ImpressCMS path traversal to pre-auth RCE 15-02 CVE CVE-2022-24977 - ImpressCMS path traversal to pre-auth RCE 12-02 POST impressCMS - unauthenticated code execution
2021 · 7
07-12 CVE CVE-2020-36474 - Vanilla SSRF 23-11 POST Moodle Blind SQL injection via MNet authentication 22-10 POST Moodle - Stored XSS and blind SSRF possible via feedback answer text 20-08 POST Vanilla - SSRF via media scrape API through dns rebinding 22-07 CVE CVE-2021-36396 - Moodle Blind SSRF possible against cURL blocked hosts 17-05 CVE CVE-2021-32474 - Moodle Blind SQL injection via MNet authentication 17-05 POST 3kCTF-2021 - ppaste writeup
2020 · 6
31-12 CVE CVE-2020-36474 - safecurl <= 3.3, vanilla forum <= 0.9.2 dns rebind to ssrf 29-09 CVE CVE-2020-26134 - Live Helper Chat before 3.44v - stored xss 25-07 EXPLOIT 3kCTF-2020 - Glitch exploit 25-07 POST 3kCTF-2020 - Glitch writeup 25-07 POST 3kCTF-2020 - reporter writeup 14-05 EXPLOIT CVE-2020-12720 - Vbulletin RCE
CONTACT
rekter0
PROFESSIONAL SLOPPER

Application security research. vulnerability disclosure, and the occasional pre-auth RCE chain.

28 CVE 7 EXPLOIT 14 POST