Open in app

Sign In

Write

Sign In

Soham Bakore
Soham Bakore

32 Followers

Home

About

Pinned

A Journey called OSCP!

Hi Guys, hope you and your loved ones are safe and doing well😊. Today I will be sharing how I prepared for one of the toughest but considered beginner level certification in the cybersecurity domain - Offensive Security Certified Professional(OSCP) and cleared it in the first attempt. I am truly…

Oscp

13 min read

A Journey called OSCP!
A Journey called OSCP!
Oscp

13 min read


Feb 4, 2021

Multiple vulnerabilities in b2evolution version: 6.11.6-stable

Vulnerability Details: 1. Reflected XSS in tab_type parameter in evoadm.php Steps to Reproduce: 1. Send the following URL : http://127.0.0.1/evoadm.php?ctrl=items&tab=type&tab_type=qnfya%22onmouseover%3d%22alert(document.domain)%22style%3d%22position%3aabsolute%3bwidth%3a100%25%3bheight%3a100%25%3btop%3a0%3bleft%3a0%3b%22gl4q0&filter=restore&blog=7 to the logged in victim. 2. When the victim opens the above link, Javascript code will be triggered

1 min read

1 min read


Feb 21, 2020

Multiple Critical Vulnerabilities Identified in an Indian Carpool Service Provider!

Hi everyone, hope you are doing well. Today I will share few of my recent critical findings regarding one of the famous and rapidly growing carpool service providers in India. Some of these vulnerabilities include withdrawing money from any user’s account without their interaction, cancelling other user’s posted rides, OTP…

Cybersecurity

7 min read

Multiple Critical Vulnerabilities Identified in an Indian Carpool Service Provider!
Multiple Critical Vulnerabilities Identified in an Indian Carpool Service Provider!
Cybersecurity

7 min read

Soham Bakore

Soham Bakore

32 Followers
Following
  • Vaibhav Kumar Srivastava

    Vaibhav Kumar Srivastava

  • Shashank

    Shashank

  • Gökhan Güzelkokar

    Gökhan Güzelkokar

  • Shahmeer Amir

    Shahmeer Amir

  • The Mobile Security Guys

    The Mobile Security Guys

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech