Pocas Notes.

Dreamhack, Leak all write ups via IDOR


The article is about IDOR Vulnerability in Dreamhack. the bug allows to leak all of write ups
Read more ⟶

0-Day, Cross-Site Scripting via markdown syntax (Vditor)


The article is about 0-day, XSS vulnerability in Vditor. I got two cves as CVE-2022-0341, CVE-2022-0350 for the bugs
Read more ⟶

Line CTF 2022 Write Up


This article is about write-up for the Line ctf 2022. there is only two web challenges, which contain an SSTI and XSS bug
Read more ⟶

Spring GoN Open Qual CTF 2022 Write Up


This article is about write-up for the Spring GoN Open Qual CTF 2022. there is only two web challenges, both of which contain an Prototype Pollution and RCE bug
Read more ⟶

Total.js CMS, Cross-Site Scripting


The article is about 0-day, XSS vulnerability in Total.js. It was simple xss
Read more ⟶