I'm 0xAdham, a Web CTF Player & Bug Bounty Hunterhuntingvulnerableweb apps forbugs
vulnerable
web apps forEgypt โข UTC/GMT +2
About Me
Location
๐ช๐ฌ Egypt
Stacks
Fav. tool
Latest Articles
Article

--
EYCC: Mall Albostan
A search box concatenates SQL, so we UNION out the JWT secret, forge an admin token, sneak a .phtml shell past a blacklist, and pivot through a UTF-16 XXE to find where it landed. SQLi to RCE, end to end.
Article

--
EYCC: EduSVG
The ID-card renderer trusted client-side SVG dimensions and piped them straight into a shell. rsvg-convert never stood a chance.
