lfi

18 articles
Sort: New Top Best
clear filter
0
blog.harshjaiswal.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability

MySQL clients can be abused via the LOAD DATA LOCAL INFILE feature to exfiltrate arbitrary files from the client machine by setting up a fake MySQL server that bypasses authentication and sends malicious payloads. This exploitation technique works because MySQL clients trust server-sent commands after authentication, allowing attackers to read sensitive files like /etc/hosts from compromised systems.

MySQL PHP 7.0.32 MySQL 8.0.13 MySQL 5.7.24
vesiluoma.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability

A Local File Inclusion (LFI) vulnerability was discovered in Nokia Maps that allowed reading arbitrary files from the server (e.g., /etc/passwd). The vulnerability was reported on January 2, 2013, and patched by Nokia on January 20, 2013.

Nokia Maps Nokia Lumia 920 Shashank
blog.shashank.co · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
hassankhanyusufzai.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
lfi
cyberzombie.in · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
lfi
nirmaldahal.com.np · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
lfi
offensi.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0

A researcher discovered a local file inclusion (LFI) vulnerability on Google's production servers at springboard.google.com through directory enumeration and authorization bypass, escalating from an initial auth bypass to full LFI with admin privileges, ultimately earning a $13,337 bounty from Google's Vulnerability Reward Program.

Omar Espino omespino Google springboard.google.com cloudsearch.google.com Google VRP wfuzz domained masscan SecLists ESCAL8 Intigriti HackerOne CVE-2024-1234
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
rcesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
rcesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
CVE-2017-0199 CVE-2017-11882 CVE-2018-0802 CVE-2019-13272 CVE-2021-22555 CVE-2022-0847 CVE-2023-32233 CVE-2023-38831 CVE-2025-11001 CVE-2025-24990 CVE-2025-49844 CVE-2025-54100 CVE-2025-55182 CVE-2025-59287 CVE-2025-6218 CVE-2025-8088
securelist.com · Alexander Kolesnikov · 6 days ago · details
0
CVE-2026-0651 CVE-2026-0652 CVE-2026-0653
spaceraccoon.dev · spaceraccoon · 6 days ago · details
0
blog.fadyothman.com · Fady Othman · 126 years ago · details