express 9
- FFmpeg Argument Injection Leads to Arbitrary File Read | Splice
- Exposed Git Repository Leads to Header-Based Admin Bypass | Packed
- Path Traversal Leads to Access Control Bypass | Gassed Up
- NoSQL Injection Leads to Authentication Bypass | Smoothie
- LDAP Injection Leads to Authentication Bypass | MeltDown
- LDAP Injection – Hidden Registrar Archive Disclosure | Saint Croix University
- Broken Access Control – Role Manipulation via User Registration | Tanuki
- Command Injection – Remote Code Execution via rollOptions Parameter | Diceforge
- File Inclusion – Arbitrary File Read via Image Endpoint | Ottergram