File tree
190 files changed
+13300
-135
lines changed- 2020
- 02/24/Mutation XSS in Mozilla-bleach via noscript
- 03/16/Mutation XSS in Mozilla-bleach via svg or math
- 07/07/Mutation Cross-Site Scripting (mXSS) Vulnerabilities Discovered in Mozilla-Bleach
- 08/19
- Codiad CSRF in the plugin request
- Codiad SSRF when installing a plugin
- Stored XSS via folder name in Codiad
- 11
- 17/Reintroduced ReDoS in debug
- 26/Mutation Cross-Site Scripting in lxml
- 12
- 07/CSRF in ultimate-category-excluder wordpress plugin
- 16/Open redirect in Jupyter server
- 22/RCE via site-offline wordpress plugin
- 2021
- 01
- 13/CSRF in Elementor-Contact-Form-DB wordpress plugin
- 31/Mutation XSS in Mozilla-bleach using comments
- 02
- 09/Denial of Service in get-ip-range package
- 12/Hostname spoofing in urijs
- 17/Hostname spoofing in url-parse
- 04/25
- Command injection vulnerability in curl-ganteng
- Remote code execution vulnerability in reqwest
- 05/16/Deserialization RCE attack in replicator
- 06
- 13/NPM Replicator Remote Code Execution Deserialization
- 16
- DoS in Spring Cloud Function
- Unintended function invocation in Spring Cloud Function
- 27
- Prototype pollution in cloneextend
- Prototype pollution in extend2
- 12
- 27/Apache Log4j 2.17.0 Arbitrary Code Execution via JDBCAppender DataSource Element
- 29/Deserialization attack via JDBC Appender in log4j
- 2022/06/26/Spring Function Cloud DoS (CVE-2022-22979) and Unintended Function Invocation
- 2023
- 05/15/Pimcore- One click, two security vulnerabilities
- 07
- 03/Vendure admin-ui-plugin authenticated Cross-site Scripting
- 11/Vendure Cross Site Request Forgery vulnerability impacting all API requests
- 25/Typo3 HTML Sanitizer By-passing via the noscript tag
- 08
- 21/Playing Dominos with Moodle's Security 1
- 28/Playing Dominos with Moodle's Security 2
- 10/03/HtmlSanitizer vulnerable to Cross-site Scripting in Foreign Content
- 11
- 04/Apache httpd XSS by design
- 13
- Masterminds html5-php parser differential
- Typo3 HTML Sanitizer By-passing via the processing instructions
- 28/PHP HTML parser differential due to libxml2 lack of HTML5 support
- 12/20/SSRF in Gradio
- 2024
- 01
- 23/Excessive Expansion: Uncovering Critical Security Vulnerabilities in Jenkins
- 31/Authenticated Arbitrary File Read in Mealie
- 03
- 10/Reply to calc: The Attack Chain to Compromise Mailspring
- 31/Apache Dubbo Consumer Risks: The Road Not Taken
- 04/28/Arbitrary File Write in Resume-Matcher
- 05/26/mXSS: The Vulnerability Hiding in Your Code
- 09/02/Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
- 11/04/Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail
- 12/08/DOMPurify 3.2.1 Bypass (Non-Default Config)
- 2025
- 01
- 11/MacOS Binary Debugging
- 26/The Tainted Voyage: Uncovering Voyager's Vulnerabilities
- 06
- 25/Caught in the FortiNet: How Attackers Can Exploit FortiClient to Compromise Organizations 1
- 29/Caught in the FortiNet: How Attackers Can Exploit FortiClient to Compromise Organizations 2
- about
- advisories
- archive
- 2020
- 02
- 03
- 07
- 08
- 11
- 12
- page/2
- 2021
- 01
- 02
- 04
- 05
- 06
- 12
- page/2
- 2022
- 06
- 2023
- 05
- 07
- 08
- 10
- 11
- 12
- page/2
- 2024
- 01
- 03
- 04
- 05
- 09
- 11
- 12
- 2025
- 01
- 06
- page
- 2
- 3
- 4
- 5
- 6
- css
- img/blogs/fortinet
- 1
- 2
- page
- 2
- 3
- 4
- 5
- 6
- tags
- Fortinet
- account-take-over
- apache
- arbitrary-file-read
- arbitrary-file-write
- ato
- bypass
- page/2
- chain
- code-execution
- content-type
- csp
- csrf
- debugging
- denial-of-service
- deserialization
- disputed
- dompurify
- dos
- electron
- file-upload
- function
- ghidra
- html
- httpd
- improper-validation
- javascript
- java
- jenkins
- lldb
- log4j2
- log4j
- macos
- moodle
- mozilla
- mxss
- page/2
- nodejs
- node
- npm
- page/2
- oauth
- open-redirect
- parser-differential
- path-traversal
- php
- polyglot
- prototype-pollution
- python
- rce
- page/2
- redos
- rpc
- sandbox
- sop
- spoofing
- sqli
- ssrf
- unauthenticated
- unauth
- v8
- webshell
- wordpress
- xss
- page/2
- talks
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
190 files changed
+13300
-135
lines changedLines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
Lines changed: 6 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
105 | 111 | | |
106 | 112 | | |
107 | 113 | | |
| |||
0 commit comments