Securitycipher
banner
securitycipher.bsky.social
Securitycipher
@securitycipher.bsky.social
📃 Write-ups and Resources 🚀 related to Bug Bounty💲 #bugbounty #bugbountytips
November 11, 2025 at 9:07 PM
November 11, 2025 at 6:13 PM
libcurl FTP path normalization flaw allows decoded %2e%2e CWD .. and directory escape (Path Traversal, CWE-22)

https://hackerone.com/reports/3418861
November 11, 2025 at 5:12 PM
November 11, 2025 at 12:18 PM
Two click Account Takeover

https://hackerone.com/reports/3079738
November 11, 2025 at 10:15 AM
November 11, 2025 at 10:10 AM
November 11, 2025 at 8:13 AM
Command Injection - CRITICISM

https://hackerone.com/reports/3418760
November 11, 2025 at 7:13 AM
November 11, 2025 at 4:13 AM
November 11, 2025 at 3:39 AM
November 11, 2025 at 12:45 AM
November 10, 2025 at 11:08 PM
November 10, 2025 at 10:09 PM
November 10, 2025 at 7:07 PM
November 10, 2025 at 6:13 PM
Arbitrary Configuration File Inclusion: via External Control of File Name or Path

https://hackerone.com/reports/3418646
November 10, 2025 at 5:12 PM
November 10, 2025 at 5:09 PM
SMTP CRLF Injection in curl/libcurl via MAIL FROM/RCPT TO parameters

https://hackerone.com/reports/3418616
November 10, 2025 at 4:17 PM
Unsafe use of strcpy in Curl_ldap_err2string (packages/OS400/os400sys.c) stack-buffer-overflow (PoC + ASan)

https://hackerone.com/reports/3418528
November 10, 2025 at 3:15 PM
November 10, 2025 at 3:10 PM
November 10, 2025 at 2:09 PM
November 10, 2025 at 1:24 PM
November 10, 2025 at 12:18 PM
SMTP CRLF Command Injection in CURLOPT_MAIL_FROM and CURLOPT_MAIL_RCPT

https://hackerone.com/reports/3414088
November 10, 2025 at 11:12 AM