Not authorized
-
-
Not authorized
-
I found a way to trigger an RCE vulnerability via confusing file extenstion in the render() function
-
Not authorized
-
Not authorized
-
Not authorized
-
Not authorized
-
Not authorized
-
Not authorized
-
Not authorized
-
Not authorized
-
I found a vulnerability that could leak all of DreamHackâs Wargame Write Up using a simple IDOR
-
Found confusing URL parsing within NPM's parser module
-
Bypass that patch using the template tag. Yea this was a simple Sanitizer bypass where I could inject an iframe, script tag
-
Trigger XSS after splReservSeq leak in purchase logic
-
The serieson.naver.com was very vulnerable to Dom Based XSS via Open Redirect * 2
-
Exposure of sensitive information in the response of the file upload process
-
The joinus.comic.naver.com was very vulnerable to Dom Based XSS
-
There was an RCE vulnerability in NASA's subdomain
-
Triggered XSS Vulnerability within Rakuten WAF Error Pages
-
There was 3 XSS vulnerabilities in ssgdfs (HackTheChallenge)
-
There was 2 XSS vulnerabilities in NCSoft's subdomain (HackTheChallenge)
-
Prototype Pollution utils.js < 0.17.2
-
The mail.kakao.com was very vulnerable to Stored XSS via Sanitizer Bypass
-
The nid.naver.com was very vulnerable to Reflected XSS via CSP Bypass
-
The www.kakao.com was vulnerable to Directory Listing and LFI
-
Triggered 3 XSS Vulnerabilities in Rakuten Services