@destro4evr@Deepaksaini7740 I use tools like FFUF and dirsearch, along with wordlists such as SecLists, selecting the appropriate wordlist based on the website’s technology
CVE-2025-52664 SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users cve.org/CVERecord?id=C…
Alhamdulillah — one of the achievements I’m most proud and happy about in 2025 🥰❤️
I discovered an SQL injection in Revive Adserver allowing low-privilege attackers full DB access. CVE-2025-52664.
Official disclosure: revive-adserver.com/security/reviv…hackerone.com/reports/3395221
@Monir_Ish I was trying to change the password on the main hacker account and noticed a parameter in the JSON for the hacker's email. I added a userID parameter to the request, and it worked! The victim's account email and password were changed
@yunxohang The challenges ended 4 months ago, but the time of reporting and submitting the report was during the challenges and the bounty awarding period, not after. However, they used a stupid excuse.