KalemSec
Home
About
Writing
Projects
2025
2025-04-26
From SSTI to SSTI to RCE - Bypassing Thymeleaf sandbox <= 3.1.3.RELEASE
2025-02-15
CVE-2025-0001
2025-01-22
VPN-in-the-browser
2024
2024-06-07
Exploiting CVE-2024-37148
2024-05-09
Exploiting CVE-2024-29889 and CVE-2024-31456
2024-03-24
Exploiting CVE-2024-27096
2024-02-29
CVE-2024-27937 - CVE-2024-27930 - Walkthrough
2023
2023-12-28
From SSRF to authentication bypass
2023-11-05
Hidden in plain sight - Part 2
2023-10-31
Hidden in plain sight
2023-09-27
Tiny File Manager - There's no place like home
2023-06-02
CVE-2023-3064, CVE-2023-3065, and CVE-2023-3066
2023-06-01
CVE-2023-3031
2023-06-01
CVE-2023-3032
2023-06-01
CVE-2023-3033
2023-02-05
FuckFastCGI made simpler
2023-02-01
PHP .user.ini risks
2023-01-30
PHP open_basedir bypass