Spring4Shell (CVE-2022-22965): A Practical Exploitation Walkthrough

How Java Bean data binding turned into remote code execution on Spring MVC applications deployed as WAR files on Tomcat.

2022-03-30 · 3 min · 492 words · lcz

ProxyLogon (CVE-2021-26855): Dissecting the Exchange SSRF Chain

Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.

2021-03-10 · 3 min · 524 words · lcz