Sysdum retweetledi

WontFix can be an RCE Goldmine
SOAPwn by @chudyPB
#5 in PortSwigger Web Hacking Techniques of 2025
Microsoft’s refusal to patch HttpWebClientProtocol invalid casting makes any .NET app using ServiceDescriptionImporter permanently vulnerable to arbitrary file write via malicious WSDLs.
Blog link 👇
labs.watchtowr.com/soapwn-pwning-…
English



























