Blog
Home on eval.blog Recent content in Home on eval.blog
vulnerability craftcms reported leak xss bypass code code execution cve-2021-27902 execution internal python Latest posts There’s an unfixed gadget living in Flask Ninja. Its HttpBearer authenticator reads the credential from a header named by a plain, writable attribute, so a deserialization sink that calls its result, or config that hydrates the auth object from untrusted data, is enough to repoint it at an internal header and leak it.
Jul 21, 2026 Exploring prompt injection techniques to extract hidden system prompts from popular AI wrappers and chatbots.
Dec 30, 2024 Reported a Denial of Service (infinite loop) vulnerability in the zipp module, which also affects Python’s built-in zipfile module (part of the standard library).
Apr 10, 2024 Reported an OAuth token leak via open redirect in Harvest.
Oct 21, 2023
AppSec Village DEF CON 31 CTF^2 (developer) winning entry. Bypassed the encryption and mutation techniques of the Mutant Language.
Aug 15, 2023 How to use unit testing frameworks like xUnit for automated vulnerability scanning and exploit development.
Jan 12, 2023 Identified a vulnerability in PHP’s FILTER_VALIDATE_URL filter by discovering a bypass that allowed an invalid URL to be validated.
Jul 29, 2021 Reported a stored cross-site scripting vulnerability in CraftCMS that was assigned CVE-2021-27902.
Jul 29, 2021 SSTI in CraftCMS, part of a chain of multiple vulnerabilities leading to RCE.
Jul 29, 2021 Reported CVE-2021-27902 (XSS) and CVE-2021-27903 (SSTI) that can be chained together to gain Remote Code Execution in CraftCMS.
Jul 28, 2021 Reported a vulnerability in PHPMailer where a function could run unexpectedly while sending a mail leading to untrusted code execution.
Jul 10, 2021 Discovered a method to leak IP addresses in a misconfigured WordPress instance (useful when targets are behind a dns firewall like CloudFlare)
Dec 26, 2020 Why data URLs are a powerful alternative to hosted JavaScript files for XSS testing and payload delivery.
Dec 26, 2020 A practical guide to traditional and dynamic importing in Python, including importlib, relative imports, and best practices.
Jun 8, 2020 Publicly disclosed vulnerability reports that did not receive CVE identifiers.
Jan 1, 1970
← Prev ✦ Random Next → Visit ↗ Feed Kagi ↗