Research 11
- IoT Dataset Research: Curating Realistic Traffic for Security Analysis
- My Journey in CVE Research: From Discovery to Disclosure
- Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated)
- Online Veterinary Appointment System v1.0 — Multiple SQL Injection via id in Appointment Details)
- Hospital's Patient Records Management System v1.0 - 'id' SQL Injection (Authenticated)
- Hospitals Patient Records Management System v1.0 — IDOR (Account Takeover)
- CVE-2021-44228 (Log4Shell) — Field Notes from a Focused Web-App Review
- WordPress Advanced Ticket System < 1.0.64 — Authenticated Stored XSS in Ticket Metadata
- WP Ticket (Customer Service Software & Support Ticket System) < 5.10.4 — Admin+ Stored XSS via Unsanitized List Fields (CVE-2021-24622)
- WP Courses LMS < 2.0.44 — Authenticated Stored XSS via 'Video Embed Code'
- Book appointment Online < 1.39 - Authenticated Stored Cross-Site Scripting (XSS)