OsCommerce v4 RCE: Unveiling the file upload bypass threat
In my recent research, I identified a critical vulnerability in osCommerce v4, specifically a Remote Code Execution (RCE) vulnerability enabled by bypassing file upload
In my recent research, I identified a critical vulnerability in osCommerce v4, specifically a Remote Code Execution (RCE) vulnerability enabled by bypassing file upload
Saudações, queridos leitores! Como estão vocês? Que o deus do hacking esteja presente em suas vidas! Brincadeiras à parte, através deste artigo, que na
Existem diferentes metodologias propostas para definir as etapas de uma avaliação da Red team. Independentemente da metodologia escolhida, a maioria concorda com a importância
Pesquisa de vulnerabilidade 1Day pela Equipe de Pesquisa da Hakai Este post trata da jornada para criar uma Prova de Conceito sobre a CVE-
Eu sou Daniel França Lima e sou pentester Jr e pesquisador de vulnerabilidades na Hakai Offensive Security. Com o objetivo de ajudar a comunidade
Abstract On February 13th, 2024, during the patch Tuesday, Microsoft disclosed the CVE-2024-21338 based on the security report made by Jan Vojtěšek
In this article, we will discuss a case of SSRF in a GCP environment and how exploiting this vulnerability led to the idea and
Greetings to all, This article aims to provide insights and stories about vulnerabilities in web applications and their impacts. Throughout this text, I will
This post details the journey of our Research Team in uncovering a SQL Injection vulnerability in GLPI, an open-source ITSM tool predominantly used