Back to directory
WRITEUP #2499

Exploiting Arbitrary Object Instantiations in PHP without Custom Classes

Privilege EscalationLack of rate limitingIDORAccount takeover
byMuhammad Talha / evilmango
Program
-
Published
Jul 15, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@evilmango/this-is-what-i-call-mass-idor-20e6ec146c0e
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Unlocking the Weak Spot: Exploiting Insecure Password Reset Tokens
RCEBruteforce
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
Escalating From Reader To Contributor In Azure API Management
Privilege Escalation
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat