php

3 articles
Sort: New Top Best
clear filter
0

An unauthenticated remote code execution vulnerability in Dell KACE K1000 Systems Management Appliance (version 6.3.113397 and earlier) exists in the /service/krashrpt.php endpoint, which fails to properly sanitize the kuid and name parameters before passing them to shell commands, allowing arbitrary code execution on the appliance and potentially all managed client endpoints. The vulnerability was silently patched by Dell in version 6.4 SP3 (6.4.120822) under bug ID K1-18652.

CVE-2019-XXXX K1-18652 Dell KACE K1000 Quest Software Inc Julien Ahrens Dropbox H1-3120
rcesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0

Step-by-step exploitation of multiple SQL injection vulnerabilities in Oculus' website, demonstrating blind SQL injection techniques with whitespace and comma filtering bypass to extract admin session credentials. The attacker chained five SQL injections together, using creative MySQL syntax (comment blocks, OFFSET instead of comma-based LIMIT) to gain administrator access without prepared statements.

Oculus Facebook Josip Franjković Jon Bitquark developer.oculusvr.com CompanyAction.php Burp sqlmap
josipfranjkovic.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0 3/10

A designer-developer built Bliip, a GPS-ephemeral social network using Vanilla JS PWA, Redis spatial indexing, and client-side FFmpeg.wasm for video processing, achieving 15 active users after a year with a €30/month infrastructure budget despite technical challenges with mobile OS photo processing delays and Google Play approval friction.

Bliip FFmpeg.wasm Redis Google Play GPT-5 Claude Gemini SharedArrayBuffer COOP/COEP
fariniasty · 9 hours ago · details · hn