<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://kelvin-0110.github.io/posts/net-sec-challenge/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/broken-access-control-unprotected-admin-panel/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/broken-access-control-unprotected-admin-panel-unpredictable-url/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/broken-access-control-privilege-escalation-client-controlled-cookie/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/file-path-traversal-simple-case/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/ssti-remote-code-execution-bind-shell-leaf/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/lfi-log-poisoning-remote-code-execution-venomous/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/user-id-controlled-by-request-parameter/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/user-id-controlled-by-request-parameter-password-disclosure/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/arrow-telnet-default-credentials/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/file-hunter-ftp-anonymous-access/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/secure-command-ssh-default-credentials/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/query-gate-mysql-unauthenticated-access/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/discover-lernaean-directory-enum-to-ssh-bruteforce.md/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/leaf-ssti-to-bind-shell/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/find-and-crack-glpi-rce-zip-password-cracking/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/super-process-supervisor-rce-privilege-escalation/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/glitch-nostromo-rce-dirtypipe-privilege-escalation/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/tryhackme-vulnerability-capstone/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/tryhackme-silver-platter/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/tryhackme-simple-ctf/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/tryhackme-blue/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/information-disclosure-hidden-in-plain-sight/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/broken-access-control-api-stats-manipulation-bugforge/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/idor-shared-notes-exposure-bugforge/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/file-inclusion-arbitrary-file-read-ottergram/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/command-injection-remote-code-execution-diceforge/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/broken-access-control-role-privilege-escalation-tanuki/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/broken-access-control-admin-access-token-bruteforce-gift-list/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/sql-injection-flower-webverse-lab/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/broken-auth-predictable-token-sokudo/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/lfi-arbitrary-file-read-ridgelinepress-webverse/</loc>
<lastmod>2026-06-03T09:59:38+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/idor-unauthorized-checkout-access-overdue/</loc>
<lastmod>2026-06-03T09:59:38+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/path-traversal-arbitrary-file-read-ottergram/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/union-based-sql-injection-credential-extraction/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/boolean-based-blind-sql-injection-database-extraction/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/union-based-sqli-profile-api-credential-extraction/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/predictable-token-enumeration-giftcard/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/unrestricted-file-upload-rce-config-leak/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/mime-type-bypass-unrestricted-file-upload-rce/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/file-signature-bypass-polyglot-file-upload-rce/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/file-extension-blacklist-bypass-upload-rce/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/otp-bypass-password-reset-admin-takeover-cheesy-does-it/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/tanuki-xxe-via-deck-import/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/weak-session-token-design-md5-session-hijacking-copypasta/</loc>
<lastmod>2026-06-03T09:59:38+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/jinja2-ssti-rce-sunnyside/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/predictable-time-based-auth-token-authentication-bypass-sokudo/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/uuid-based-idor-through-member-api-apex-fitness/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/graphql-introspection-and-sensitive-data-exposure-ottergram/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/jwt-alg-none-authentication-bypass-evergreen/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/cafeclub-race-condition-checkout-bypass/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/idor-order-access-unauthorized-data-exposure-hartwood-webverse/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/cheesy-does-it-idor-order-disclosure/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/nosqli-authentication-bypass-snickerdoodle/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/mapleton-lfi-sensitive-file-disclosure/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/tanuki-xinclude-arbitrary-file-read/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/server-side-template-injection-leading-to-rce-outbox/</loc>
<lastmod>2026-06-03T09:59:38+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/xxe-injection-arbitrary-file-disclosure-holloway/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/command-injection-via-filename-parameter-leading-to-rce-quotin/</loc>
<lastmod>2026-06-03T09:59:38+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/jwt-secret-cracking-and-admin-token-forgery-tally/</loc>
<lastmod>2026-06-03T09:59:38+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/mass-assignment-leading-to-admin-account-creation-trellis/</loc>
<lastmod>2026-06-03T09:59:38+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/local-file-inclusion-via-php-stream-wrappers-dockethive/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/command-injection-and-broken-function-level-authorization-newsforge/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/graphql-bola-via-introspection-and-insecure-resolver-access-slate-quarry/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/ldap-injection-hidden-registrar-archive-disclosure-saint-croix-university/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/websocket-idor-order-subscription-joy-stick/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/sqli-to-idor-admin-caretaker-beaumont/</loc>
<lastmod>2026-05-25T20:51:03+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/unrestricted-file-upload-remote-code-execution-crosswind/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/sql-injection-authentication-bypass-gatekeeper/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/weak-password-bruteforce-missing-rate-limiting-halftrack/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/stored-xss-internal-endpoint-enumeration-crate-and-sleeve/</loc>
<lastmod>2026-05-31T23:46:23+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/workflow-access-control-bypass-admin-privilege-escalation-lazy-human-resources/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/information-disclosure-debug-header-leakage-header-hunt/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/weak-password-reset-bruteforce-account-takeover-spare-key/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/client-side-price-manipulation-business-logic-flaw-snooker/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/sensitive-information-disclosure-base64-cookie-cookie-cutter/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/sql-injection-sensitive-data-exposure-vibed/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/missing-access-control-staff-portal-exposure-coltsfoot-community-center/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/ssrf-blocklist-bypass-internal-file-disclosure-cutcorner/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/x-forwarded-for-spoofing-access-control-bypass-brackish-brewing/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/ssrf-internal-service-discovery-statuscraft/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/command-injection-netcheck/</loc>
<lastmod>2026-05-23T11:00:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/cgi-os-command-injection-remote-command-execution-slash-and-sons/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/versed-sql-injection-union-database-extraction/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/candy-sqli-file-upload-rce-admin-bypass/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/graphql-information-disclosure-schematic/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/idor-account-export-data-disclosure-remittance/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/arbitrary-file-read-image-parameter-file-injection-suited/</loc>
<lastmod>2026-05-27T12:09:01+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/mass-assignment-role-escalation-salt-brook-pilates/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/unrestricted-file-upload-rce-hollow-run-bedding/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/local-file-inclusion-double-url-encoding-mirage/</loc>
<lastmod>2026-05-27T10:00:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/default-credentials-authentication-weakness-lake-forks-permits/</loc>
<lastmod>2026-05-27T18:15:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/exposed-git-repository-information-disclosure-loop-and-roam-records/</loc>
<lastmod>2026-05-27T18:30:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/information-disclosure-client-side-analytics-exposure-pebble-and-pine/</loc>
<lastmod>2026-05-28T00:00:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/reflected-cross-site-scripting-ember-kettle/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/reflected-xss-attribute-breakout-sandpiper-stationery/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/weak-credentials-account-compromise-pinegrass-library-co-op/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/nosql-injection-authentication-bypass-herbalist-remedies/</loc>
<lastmod>2026-05-28T18:00:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/information-disclosure-debug-branch-quikpay-receipts/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/jwt-none-algorithm-privilege-escalation-stargate-atlas/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/privilege-escalation-cookie-tampering-session-swap/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/privilege-escalation-unsigned-session-token-spindrift-workspace/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/reflected-xss-html-comment-breakout-fermata/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/cross-site-scripting-tag-breakout-rivet-and-tack/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/information-disclosure-html-comment-exposure-vellichor-press/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/information-disclosure-redirect-debug-comment-redirect-run/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/information-disclosure-robots-txt-exposure-sundial-observatory/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/local-file-inclusion-arbitrary-file-read-traverse/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/reflected-xss-filter-bypass-palisade/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/authentication-bypass-forged-remember-me-cookie-bump-key/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/bugvault-cve-2025-29927/</loc>
<lastmod>2026-06-09T20:31:37+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/idor-workflow-state-manipulation-briarcliff-foundation/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/os-command-injection-archive-export-filename-parchive/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/sql-injection-union-based-database-enumeration-trace-control/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/sql-injection-voucher-search-admin-voucher-disclosure-voucher-vault/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/authentication-bypass-dashboard-access-pivot-hr/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/graphql-role-parameter-privilege-escalation-clearance/</loc>
<lastmod>2026-06-03T09:48:22+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/nosql-injection-hidden-rental-disclosure-swiftsearch-hotels/</loc>
<lastmod>2026-06-06T14:44:08+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/fault-banking-exposed-git-repository-administrative-credential-disclosure/</loc>
<lastmod>2026-06-04T12:00:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/flagged-local-file-inclusion-via-language-cookie/</loc>
<lastmod>2026-06-04T13:00:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/the-oak-exiftool-cve-2021-22204-rce/</loc>
<lastmod>2026-06-05T14:45:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/autovation-unsafe-yaml-deserialization/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/tamper-temple-broken-access-control-chain/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/coined-nosql-injection-authentication-bypass/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/noted-password-reset-idor/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/halftone-studio-jwt-algorithm-confusion/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/theforms-idor-account-takeover/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/costthis-local-file-inclusion/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/foldmark-xxe-injection/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/calliope-gallery-unrestricted-file-upload/</loc>
<lastmod>2026-06-09T20:28:55+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/posts/portwart-stored-xss-session-hijacking/</loc>
<lastmod>2026-06-10T14:00:00+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/</loc>
<lastmod>2026-06-10T23:09:35+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/</loc>
<lastmod>2026-06-10T23:09:35+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/archives/</loc>
<lastmod>2026-06-10T23:09:35+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/about/</loc>
<lastmod>2026-06-10T23:09:35+05:30</lastmod>
</url>
<url>
<loc>https://kelvin-0110.github.io/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/weak-authentication/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/brute-force/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ftp/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/hydra/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/service-enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/credential-compromise/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/linux/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/tryhackme/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/nmap/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ids-evasion/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/broken-access-control/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/authorization-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/admin-panel/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/privilege-escalation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/portswigger/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/information-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cookie-manipulation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ssti/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/server-side-template-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/twig/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/remote-code-execution/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/bind-shell/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/netcat/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/hackviser/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/lfi/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/local-file-inclusion/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/directory-traversal/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/log-poisoning/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/reverse-shell/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/nginx/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/idor/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/predictable-identifiers/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/guid/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/horizontal-privilege-escalation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/password-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/sensitive-data-exposure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/default-credentials/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/telnet/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/misconfiguration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/authentication-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/root-access/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/anonymous-access/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/credential-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ssh/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/unauthenticated-access/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/mysql/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/database-exposure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/directory-enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-manager-exposure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/unauthorized-access/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/data-exposure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/glpi/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/sudo-misconfiguration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/gtfobins/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/zip-password-cracking/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/fcrackzip/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/supervisor/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2017-11610/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/suid/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/metasploit/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/nostromo/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2019-16278/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/dirty-pipe/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2022-0847/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/kernel-exploit/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/rce/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/fuelcms/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2018-16763/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/credential-leakage/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/silverpeas/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/sql-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cms-made-simple/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2019-9053/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/eternalblue/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ms17-010/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2017-0144/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/smb/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/windows/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/source-code/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/robots-txt/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/http-headers/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/security-txt/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ctf/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cybersplash2026/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/api/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/http-method/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/put/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/jwt/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/bugforge/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/base64/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-inclusion/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/path-traversal/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/arbitrary-file-read/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/express/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/command-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/input-validation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/api-testing/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/backend/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/role-manipulation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/burpsuite/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/authorization-flaw/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/token-bruteforce/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ffuf/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/gobuster/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/union-based-sqli/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/database-enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/webverse/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/authentication/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/token/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/predictable/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/account-takeover/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/access-control/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/authorization/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/insecure-direct-object-reference/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-handling/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/union-based/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/blind-sqli/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/boolean-based/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/automation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/data-extraction/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/sqli/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/sqlite/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/burp-suite/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/data-exfiltration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/token-enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/predictable-values/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/business-logic/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/api-security/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/insecure-design/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-upload/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/php/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/mime-type-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-signature-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/polyglot-file/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/blacklist-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/phar/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/otp-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/broken-authentication/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/logic-flaw/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/xxe/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/xml/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-read/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/insecure-parser/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/content-type-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/session-hijacking/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/weak-session-management/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/md5/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cookie-security/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/hashcat/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/jinja2/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/flask/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/python/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/command-execution/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/webversepro/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/predictable-token/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/local-storage/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/uuid/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/graphql/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/introspection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/alg-none/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/insecure-authentication/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/session-management/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/race-condition/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/checkout-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cart-manipulation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/parallel-requests/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/nosql-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/mongodb/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/expressjs/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/json-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/xinclude/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/template-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/xml-external-entity/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/weak-secret/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/mass-assignment/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/php-stream-wrapper/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/bfla/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/nodejs/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/bola/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ldap-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/openldap/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/websocket/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/auth-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/unrestricted-upload/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/extension-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/webshell/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/login-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/bruteforce/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/weak-passwords/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/missing-rate-limit/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/credential-attack/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/xss/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/stored-xss/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/endpoint-enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/javascript-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/workflow-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/debug-header/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/response-header/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/reconnaissance/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/password-reset/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/credential-reset/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/price-manipulation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/client-side-validation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cookie-tampering/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/privilege-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cookies/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/missing-authorization/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/forced-browsing/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/robots-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/staff-portal/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/ssrf/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/blocklist-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/localhost-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/internal-service-discovery/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/x-forwarded-for/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/header-spoofing/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/trust-boundary/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/proxy-misconfiguration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/localhost-access/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/port-scanning/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/network-enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/webverselabs-pro/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/os-command-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/web-security/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cgi/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/os-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/legacy-systems/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/security-misconfiguration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/account-export/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/file-uri-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/api-abuse/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/image-parameter/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/role-escalation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/unrestricted-file-upload/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/double-encoding/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/credential-management/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/git/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/exposed-git/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/source-code-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/javascript/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/client-side/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/analytics/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/source-code-review/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/reflected-xss/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/attribute-breakout/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/html-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/authentication-failures/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/weak-credentials/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/username-enumeration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/nosql/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/debug-mode/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/content-type/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/receipts/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/jwt-none/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/token-tampering/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/session-token/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/html-comment/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/tag-breakout/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/html-comments/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/redirects/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/debug-comments/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/sensitive-files/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/filter-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/remember-me-cookie/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/bugvault/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/nextjs/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/middleware/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2025-29927/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/workflow-manipulation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/mariadb/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/information-schema/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/mfa-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/direct-access/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/healthcare/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/operator-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/git-exposure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/webverse-pro/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/the-oak/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/exiftool/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cve-2021-22204/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/djvu/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/supply-chain/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/method-override/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/tamper-temple/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/coined/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/noted/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/jwt-confusion/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/hs256/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/rs256/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/halftone-studio/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/theforms/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/costthis/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/foldmark/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/web-shell/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/calliope-gallery/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/cookie-theft/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/tags/admin-takeover/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/penetration-testing/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/web-application-exploitation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/a01-broken-access-control/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/missing-authorization/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/privilege-escalation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/a05-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/ssti/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/a02-security-misconfiguration/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/local-file-inclusion/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/idor/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/linux-privilege-escalation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/linux-priviledge-escalation/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cve-2017-11610-supervisor-xml-rpc-rce/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cve-2019-16278-nostromo-rce/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cve-2018-16763-fuel-cms-rce/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cve-2019-9053-cms-made-simple-sql-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cve-2017-0144-eternalblue-rce/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/information-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/authorization-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/command-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/broken-access-control/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/sql-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/a07-authentication-failures/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/broken-authentication/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/path-traversal/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/a06-insecure-design/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/business-logic-abuse/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/unrestricted-file-upload/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/otp-authentication/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/weak-session-management/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/jwt/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/graphql-authorization/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/race-condition/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/nosql-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/xxe/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/mass-assignment/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/bola/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/ldap-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/password-brute-force/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/stored-cross-site-scripting/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/weak-authentication/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/a04-cryptographic-failures/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/sensitive-information-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/ssrf/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/access-control-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/os-command-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/graphql-information-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/uri-injection/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/weak-credentials/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cross-site-scripting-xss/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/authentication-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cve-2025-29927-next-js-middleware-authorization-bypass/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/source-code-disclosure/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/cve-2021-22204-arbitrary-code-execution-via-exiftool/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/categories/xml-external-entity/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page2/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page3/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page4/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page5/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page6/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page7/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page8/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page9/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page10/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page11/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page12/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page13/</loc>
</url>
<url>
<loc>https://kelvin-0110.github.io/page14/</loc>
</url>
</urlset>
