ctf 12
- PHP Object Injection Leads to Arbitrary File Write | Archived
- FFmpeg Argument Injection Leads to Arbitrary File Read | Splice
- LDAP Injection Leads to Authentication Bypass and Blind Secret Extraction | Bound
- ZIP Slip Leads to Arbitrary File Write | Zippy
- Command Injection Leads to Remote Code Execution | TheFallen
- Locked - Exposed Git Repository to Authentication Bypass | Locked"
- KrissCut — SQL Injection | KrissCut
- MooKoo — Server-Side Template Injection to RCE | Mookoo
- Password Reset Poisoning via Referer Header Injection | Grifted
- GraphQL SQL Injection to JWT Admin Forgery | SweetCore
- NoSQL Injection to Mass Assignment Admin Takeover | Expensiel
- Information Disclosure – Sensitive Data Exposure via Source Code, Headers & Public Files | Hidden in Plain Sight