🚨 CVE-2025-49113 – Roundcube Post-Auth RCE
A deep technical dive into how the _from parameter in upload.php enables PHP object deserialization leading to remote code execution.
Read the full write-up here 👇
nullsecurityx.codes/cve-2025-49113…#PHP#RCE#BugBounty#CyberSecurity
Second-Order SQL Injection
1️⃣ Attacker injects payload into a field that is stored in DB (e.g., username).
2️⃣ Later, another query uses this stored value unsafely.
3️⃣ Payload executes → data leak, auth bypass, or privilege escalation.
#SQLi#BugBounty#WebSecurity
YouTube shut down my ethical hacking & cybersecurity channel with 10,000 subscribers… 😅
I’ve connected my videos to Odysee, synchronization is in progress.
Do you think I’ll face the same surprise here? 🤔
@OdyseeTeam
One Message = Full Exploit! 🚨
New video is live:
⚡ The Hidden Danger in Chat Apps: Advanced XSS Exploitation (Live Bug Bounty | BMW PoC)
🔗 youtu.be/CejJWjyokFA
Learn how a simple chat message can lead to XSS → Account Takeover → Full Compromise 🔥
#BugBounty#XSS
Stored XSS via File Metadata
1️⃣ User uploads image with malicious payload in EXIF metadata (e.g., Title or Comment).
2️⃣ Application displays metadata without sanitization.
3️⃣ Payload executes in victim’s browser.
#XSS#BugBounty#AppSec
4K Followers 810 FollowingI break down #malware so you don’t have to 👾
Lead Security Researcher @Acronis TRU-Labs doing #ThreatIntel #CTI
GReAT past, and even greater challenges ahead
14 Followers 583 FollowingNew bug bounty hacker and API security enthusiast. Passionate about finding and reporting security vulnerabilities. Always looking for new challenges and ways
134 Followers 1K FollowingI post history, AI, and science content, just whatever I find interesting. The problem is I have too many interests and not enough lifetimes. 🏰⏳️
1K Followers 3K FollowingPolitólogo/Admin Público | Escritor Independiente | Jurista | Ciberseguridad | 🇲🇽 | Partido Nacional Republicano | A la patria se le sirve, no se le cobra.
4K Followers 810 FollowingI break down #malware so you don’t have to 👾
Lead Security Researcher @Acronis TRU-Labs doing #ThreatIntel #CTI
GReAT past, and even greater challenges ahead
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
190K Followers 0 FollowingWe make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!
78K Followers 4 FollowingLaunch your own channel | Watch, view, and share content | We ❤️ our creators | For help @OdyseeHelp | Available on Web, Android & iOS
17K Followers 3K FollowingCo-Founder of @CygentaHQ former head of cyber research @Raytheon - Keynote Speaker, ethical hacker and physical security specialist. Author of How I Rob Banks.
13K Followers 5K Followingex @Microsoft Security Researcher| Vulnerability Research | Threat Intel | EASM | DE | Penetration Tester | Opinions here are solely mine not my employer
6K Followers 3K Followingxss0r
Deploying an alert box in a web app is like having a tiny pop-up comedian shout 'Surprise!' whenever you least expect it!
#xss0r #ibrahimXSS #Blindxss0r
48K Followers 452 FollowingSecurity researcher with a focus on hardware & firmware. I occasionally publish stuff on YouTube. Co-founder of @hextreeio. Contact: [email protected]
2K Followers 400 FollowingFirst, I am a guy | Wireless Pentester 📡 | Docker Freak 🐳 | Exploring IoT/Hardware Hacking 🔧 | Love making custom stuffs | Building SigilShield
36K Followers 2K FollowingExpert web3 bug bounty and crowdsourced audit platform with 220 programs and over 20 million in bounty
DS: https://t.co/41lshly4dI
YT: https://t.co/cLUr6ODztP