⤷ Title: SSI (Server Side Include)and SSI Injection
════════════════════════
𐀪 Author: Zodiac
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 13:09:07 GMT
════════════════════════
⌗ Tags: #vulnerability #hacking #web #server_side #server_side_include
════════════════════════
𐀪 Author: Zodiac
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 13:09:07 GMT
════════════════════════
⌗ Tags: #vulnerability #hacking #web #server_side #server_side_include
Medium
SSI (Server Side Include)and SSI Injection
What is SSI?
It is a feature that allows developers to dynamically generate web content by using “#” directives without having to do it…
It is a feature that allows developers to dynamically generate web content by using “#” directives without having to do it…
⤷ Title: Server-side request forgery (SSRF)
════════════════════════
𐀪 Author: Zodiac Hacker
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:59:30 GMT
════════════════════════
⌗ Tags: #bug_bounty #server_side #ssrf #vulnerability #hacking
════════════════════════
𐀪 Author: Zodiac Hacker
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:59:30 GMT
════════════════════════
⌗ Tags: #bug_bounty #server_side #ssrf #vulnerability #hacking
Medium
Server-side request forgery (SSRF)
SSRF attacks can be challenging to detect because the requests come from a legitimate server, making them look like normal traffic.
⤷ Title: JWT attacks
════════════════════════
𐀪 Author: Zodiac Hacker
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:58:29 GMT
════════════════════════
⌗ Tags: #vulnerability #server_side #web #ssrf #hacking
════════════════════════
𐀪 Author: Zodiac Hacker
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:58:29 GMT
════════════════════════
⌗ Tags: #vulnerability #server_side #web #ssrf #hacking
Medium
JWT attacks
How it normally works vs How jwt works (nothing saved in server).
⤷ Title: API7:2023 — Server-Side Request Forgery: API’yi İç Sistemlere Köprü Olarak Kullanmak
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 04:16:27 GMT
════════════════════════
⌗ Tags: #server_side_request #apifort #owasp_api_security_top_10 #cybersecurity #ssrf
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 04:16:27 GMT
════════════════════════
⌗ Tags: #server_side_request #apifort #owasp_api_security_top_10 #cybersecurity #ssrf
Medium
🚨API7:2023 — Server-Side Request Forgery: API’yi İç Sistemlere Köprü Olarak Kullanmak
1. Giriş
⤷ Title: Understanding SQL Injection: Basics, Types, and How to Prevent It
════════════════════════
𐀪 Author: HackLog
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 13:24:20 GMT
════════════════════════
⌗ Tags: #server_side_security #sql_injection #example #mitigation #types_of_sql_injection
════════════════════════
𐀪 Author: HackLog
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 13:24:20 GMT
════════════════════════
⌗ Tags: #server_side_security #sql_injection #example #mitigation #types_of_sql_injection
Medium
Understanding SQL Injection: Basics, Types, and How to Prevent It
Hey everyone!
⤷ Title: TryHackMe Walkthrough: Include
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 02:44:57 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #web_application_hacking #ethical_hacking #include_thm_writeup #server_side_vulnerability
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 02:44:57 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #web_application_hacking #ethical_hacking #include_thm_writeup #server_side_vulnerability
Medium
TryHackMe Walkthrough: Include
Use your server exploitation skills to take control of a web app (Link to TryHackMe room here)
⤷ Title: CVE-2025-61927 (CVSS 9.4): Critical RCE Flaw Discovered in Happy DOM, Over 2.7 Million Weekly Downloads Impacted
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_61927 #Happy DOM #Node.js #rce #Server_Side Rendering #VM Escape
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_61927 #Happy DOM #Node.js #rce #Server_Side Rendering #VM Escape
Daily CyberSecurity
CVE-2025-61927 (CVSS 9.4): Critical RCE Flaw Discovered in Happy DOM, Over 2.7 Million Weekly Downloads Impacted
A Critical (CVSS 9.4) flaw in Happy DOM allows untrusted JavaScript to escape the Node.js VM context and achieve RCE on the host system via the Function inheritance chain.
⤷ Title: Zimbra Issues Emergency Patch for Critical SSRF Vulnerability in Chat Proxy Configuration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 08:54:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chat Proxy #cybersecurity #Server_Side Request Forgery #ssrf #Zimbra #Zimbra 10.1.x
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 08:54:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chat Proxy #cybersecurity #Server_Side Request Forgery #ssrf #Zimbra #Zimbra 10.1.x
⤷ Title: Lab 1: Basic server-side template injection (Server-side template injection)
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 12:23:43 GMT
════════════════════════
⌗ Tags: #server_side_injection #server_side_template #burpsuite #portswigger_lab #ssrf
════════════════════════
𐀪 Author: L4V4NY4 AGR3
════════════════════════
ⴵ Time: Thu, 06 Nov 2025 12:23:43 GMT
════════════════════════
⌗ Tags: #server_side_injection #server_side_template #burpsuite #portswigger_lab #ssrf
Medium
Lab 1: Basic server-side template injection (Server-side template injection)
This lab is vulnerable to server-side template injection due to the unsafe construction of an ERB template.
⤷ Title: Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:32:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_61686 #React Router #Remix Framework #Server_Side Rendering (SSR) #Session Hijacking #Web Security #XSS (Cross_Site Scripting)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:32:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_61686 #React Router #Remix Framework #Server_Side Rendering (SSR) #Session Hijacking #Web Security #XSS (Cross_Site Scripting)
Daily CyberSecurity
Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
Developers relying on the popular React Router library are being urged to patch their applications immediately following the disclosure of multiple high-severity vulnerabilities. The flaws, rangin…
⤷ Title: CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25526 #ForTag Vulnerability #HubSpot CMS #Java Template Engine #Jinjava #ObjectMapper Deserialization #Patch Alert #Remote Code Execution #Sandbox Escape #Server Side Template Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:21:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25526 #ForTag Vulnerability #HubSpot CMS #Java Template Engine #Jinjava #ObjectMapper Deserialization #Patch Alert #Remote Code Execution #Sandbox Escape #Server Side Template Injection
Daily CyberSecurity
CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution
Critical Jinjava flaw CVE-2026-25526 (CVSS 9.8) breaks sandbox security. Attackers can execute Java code via template loops. Update to v2.8.3 now.
⤷ Title: Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:14:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CVE_2026_27739 #Frontend Security #HttpClient #infosec #Patch Alert #Server_Side Request Forgery #SSR #ssrf #Vulnerability #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:14:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CVE_2026_27739 #Frontend Security #HttpClient #infosec #Patch Alert #Server_Side Request Forgery #SSR #ssrf #Vulnerability #Web Security
Daily CyberSecurity
Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing
Angular patches a critical 9.2 CVSS SSRF vulnerability (CVE-2026-27739). Attackers can manipulate Host headers to steal credentials and probe internal networks.
⤷ Title: High-Severity SSRF Flaw Uncovered in Angular’s Server-Side Rendering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@angular/platform_server #Angular #CVE #infosec #javascript #Origin Hijacking #Server_Side Rendering #SSR #ssrf #TypeScript #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@angular/platform_server #Angular #CVE #infosec #javascript #Origin Hijacking #Server_Side Rendering #SSR #ssrf #TypeScript #Web Security
Daily CyberSecurity
High-Severity SSRF Flaw Uncovered in Angular’s Server-Side Rendering
Angular patches a critical 8.7 SSRF flaw in @angular/platform-server. Attackers can hijack SSR origins via URL normalization. Patch v19, v20, or v21 now!
⤷ Title: Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
Daily CyberSecurity
Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
Thymeleaf 3.1.4 fixes two critical 9.1 CVSS vulnerabilities. Unauthenticated attackers can bypass security for SSTI. Audit your user input and patch today!
⤷ Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Daily CyberSecurity
CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
CVE-2026-33626: A critical SSRF in LMDeploy exploited in under 13 hours. Learn how attackers hijack AI nodes and how to secure your inference cloud now.
⤷ Title: GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 02:02:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Argo CD #cloud_native #CVE_2026_42880 #cybersecurity #data leak #GitOps #infosec #Kubernetes #Kubernetes Secrets #Patch Alert #Server_Side Diff
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 02:02:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Argo CD #cloud_native #CVE_2026_42880 #cybersecurity #data leak #GitOps #infosec #Kubernetes #Kubernetes Secrets #Patch Alert #Server_Side Diff
Daily CyberSecurity
GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets
A critical 9.6 CVSS flaw in Argo CD (CVE-2026-42880) allows read-only users to extract plaintext Kubernetes secrets via Server-Side Diffs. Patch to v3.3.9 now!