⤷ Title: Stored XSS via SVG File Upload in a Project Management Application
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bug_bounty #file_upload #seurity #xss_attack
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bug_bounty #file_upload #seurity #xss_attack
Medium
Stored XSS via SVG File Upload in a Project Management Application
Bug Bounty Write-up | Stored XSS | File Upload Security
⤷ Title: Windows to Linux — 5 File Transfer Techniques for Pentesting Exams
════════════════════════
𐀪 Author: Aman Chauhan
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 16:36:44 GMT
════════════════════════
⌗ Tags: #pentesting #file_transfer #ethical_hacking #oscp #cybersecurity
════════════════════════
𐀪 Author: Aman Chauhan
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 16:36:44 GMT
════════════════════════
⌗ Tags: #pentesting #file_transfer #ethical_hacking #oscp #cybersecurity
Medium
Windows to Linux — 5 File Transfer Techniques for Pentesting Exams
Hey guys, in this writeup we’re going to look at 5 file transfer techniques that will help you transfer files from Windows to Linux. These…
⤷ Title: Unauthenticated RCE in CKFinder via Null Byte Injection Vulnerability
════════════════════════
𐀪 Author: Ali İltizar
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 21:44:30 GMT
════════════════════════
⌗ Tags: #file_upload_bypass #rce #misconfiguration
════════════════════════
𐀪 Author: Ali İltizar
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 21:44:30 GMT
════════════════════════
⌗ Tags: #file_upload_bypass #rce #misconfiguration
Medium
Unauthenticated RCE in CKFinder via Null Byte Injection Vulnerability
During an authorized penetration test on a corporate web application, I was performing directory enumeration against the target when I came…
⤷ Title: From File Upload to Admin Account Takeover: Exploring Blind XSS via Malicious File Content
════════════════════════
𐀪 Author: Orion
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 14:16:54 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #penetration_testing #xss_attack #bug_bounty #web_application_security
════════════════════════
𐀪 Author: Orion
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 14:16:54 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #penetration_testing #xss_attack #bug_bounty #web_application_security
Medium
From File Upload to Admin Account Takeover: Exploring Blind XSS via Malicious File Content
Hi, I’m Hashem Ali Kahil , Orion7715
⤷ Title: HTB Machine Walkthrough: Magic
════════════════════════
𐀪 Author: Balachandar Gowrisankar
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 16:56:07 GMT
════════════════════════
⌗ Tags: #htb_writeup #sql_injection #file_upload_vulnerability #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Balachandar Gowrisankar
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 16:56:07 GMT
════════════════════════
⌗ Tags: #htb_writeup #sql_injection #file_upload_vulnerability #cybersecurity #penetration_testing
Medium
HTB Machine Walkthrough: Magic
Magic is a medium difficulty HTB machine which involves SQL injection attack, arbitrary file upload and SUID binary exploitation.
⤷ Title: The File That Answered Back — XXE Hidden in Cell A2
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:28:59 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 06:28:59 GMT
════════════════════════
⌗ Tags: #xml #bug_bounty_writeup #bug_bounty #file_upload_vulnerability #xxe
Medium
The File That Answered Back — XXE Hidden in Cell A2
Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML…
⤷ Title: From SQL Injection to Remote Code Execution: A Complete Security Assessment of the NovaCRM CTF
════════════════════════
𐀪 Author: Rajkumaryarra
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:11:30 GMT
════════════════════════
⌗ Tags: #vulnerability #rce_vulnerability #login_bypass #sql_injection #file_upload_vulnerability
════════════════════════
𐀪 Author: Rajkumaryarra
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 17:11:30 GMT
════════════════════════
⌗ Tags: #vulnerability #rce_vulnerability #login_bypass #sql_injection #file_upload_vulnerability
Medium
From SQL Injection to Remote Code Execution: A Complete Security Assessment of the NovaCRM CTF
By Raj Kumar
⤷ Title: File Inclusion Challenge (TryHackMe)
════════════════════════
𐀪 Author: Никита Ивашенюта
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 17:10:47 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #file_inclusion
════════════════════════
𐀪 Author: Никита Ивашенюта
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 17:10:47 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #file_inclusion
Medium
File Inclusion Challenge (TryHackMe)
How I Cracked the TryHackMe File Inclusion Challenges: A Deep Dive into LFI, Cookies, and $_REQUEST Bypasses
⤷ Title: File Upload Bypass On Indrive
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
Medium
File Upload Bypass Using a Pre-Signed S3 URL
welcome to my first write-up. I started bug hunting about 3 months ago, and this was one of my first findings, so I would love to share it.
⤷ Title: The Unseen Share: How I Downloaded Every File on 9 Tail Fox
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 09:18:44 GMT
════════════════════════
⌗ Tags: #abc #file_sharing #idor #bug_bounty
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 09:18:44 GMT
════════════════════════
⌗ Tags: #abc #file_sharing #idor #bug_bounty
Medium
The Unseen Share: How I Downloaded Every File on 9 Tail Fox
An IDOR vulnerability in shared links, a $700 bounty, and the invisible permission that wasn’t there