41554 blogs · [ { "id": "01a08775-9bf4-7090-aea8-ba113d1b5594", "title": "Leaking internal headers in Flask Ninja with deserialization", "url": "https://eval.blog/research/pickle-gadget-chain-in-flask-ninja/", "published_at": "2026-07-21T05:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245d1ba93d", "title": null, "url": "https://eval.blog/categories/", "published_at": "2026-07-21T05:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245d6aedeb", "title": null, "url": "https://eval.blog/", "published_at": "2026-07-21T05:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245db3dd3b", "title": null, "url": "https://eval.blog/categories/research/", "published_at": "2026-07-21T05:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245e362afb", "title": null, "url": "https://eval.blog/research/", "published_at": "2026-07-21T05:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245e66ff83", "title": null, "url": "https://eval.blog/categories/web/", "published_at": "2026-07-21T05:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245eca2b32", "title": null, "url": "https://eval.blog/legal/cookies/", "published_at": "2026-07-19T00:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245eed9669", "title": null, "url": "https://eval.blog/legal/", "published_at": "2026-07-19T00:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245f9a58ea", "title": null, "url": "https://eval.blog/legal/privacy/", "published_at": "2026-07-19T00:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9245ff8f637", "title": null, "url": "https://eval.blog/legal/terms/", "published_at": "2026-07-19T00:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9246062e041", "title": null, "url": "https://eval.blog/tutorials/", "published_at": "2026-02-19T19:00:09+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a924608888ff", "title": null, "url": "https://eval.blog/legal/disclaimer/", "published_at": "2025-07-10T00:00:00+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba113dd32bf4", "title": "Simple Prompts to get the System Prompts", "url": "https://eval.blog/blog/simple-prompts-to-get-the-system-prompts/", "published_at": "2024-12-30T03:02:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9246165d5ed", "title": "Artificial Intelligence", "url": "https://eval.blog/categories/artificial-intelligence/", "published_at": "2024-12-30T03:02:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a924617eae25", "title": null, "url": "https://eval.blog/categories/blog/", "published_at": "2024-12-30T03:02:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a92461eaf8bb", "title": "Blog Posts", "url": "https://eval.blog/blog/", "published_at": "2024-12-30T03:02:00+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba113e264847", "title": "CVE-2024-5569: Denial of Service in Zipp (and Zipfile module of Python's standard library)", "url": "https://eval.blog/cves/cve-2024-5569/", "published_at": "2024-04-10T00:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a92463ed5824", "title": null, "url": "https://eval.blog/categories/cves/", "published_at": "2024-04-10T00:00:00+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a92464adcc46", "title": null, "url": "https://eval.blog/cves/", "published_at": "2024-04-10T00:00:00+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba113e50f050", "title": "Stealing OAuth tokens of connected Microsoft accounts via open redirect in Harvest App", "url": "https://eval.blog/research/microsoft-account-token-leaks-in-harvest/", "published_at": "2023-10-21T17:03:40+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba113f121162", "title": "Breaking The Mutant Language's \"Encryption (Writeup)\"", "url": "https://eval.blog/research/breaking-the-mutant-languages-encryption/", "published_at": "2023-08-15T06:13:36+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9246643d41f", "title": "Compilers, Interpreters and Languages", "url": "https://eval.blog/categories/compilers-interpreters-and-languages/", "published_at": "2023-08-15T06:13:36+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba113f3489e1", "title": "Utilizing unit testing frameworks as a vulnerability scanner", "url": "https://eval.blog/blog/utilizing-unit-tests-as-a-vulnerability-scanner/", "published_at": "2023-01-12T10:31:05+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a924664cc8bd", "title": null, "url": "https://eval.blog/categories/programming/", "published_at": "2023-01-12T10:31:05+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba113ff6c3b0", "title": "CVE-2021-21705: FILTER_VALIDATE_URL bypass in PHP", "url": "https://eval.blog/cves/cve-2021-21705/", "published_at": "2021-07-29T00:00:00+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba1140bce680", "title": "CVE-2021-27902: Cross Site Scripting in CraftCMS", "url": "https://eval.blog/cves/cve-2021-27902/", "published_at": "2021-07-29T00:00:00+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba11412104ec", "title": "CVE-2021-27903: Server Side Template Injection in CraftCMS", "url": "https://eval.blog/cves/cve-2021-27903/", "published_at": "2021-07-29T00:00:00+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba1141f9b24f", "title": "CraftCMS Zero-day Chain: XSS to SSTI triggering RCE", "url": "https://eval.blog/research/craftcms-zero-day-ssti-xss-triggering-rce/", "published_at": "2021-07-28T23:50:38+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a92467ec005f", "title": "CMS, CRM and Forums", "url": "https://eval.blog/categories/cms-crm-and-forums/", "published_at": "2021-07-28T23:50:38+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba114274173b", "title": "CVE-2021-3603: Untrusted Code Execution in PHPMailer", "url": "https://eval.blog/cves/cve-2021-3603/", "published_at": "2021-07-10T00:00:00+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba1142d8ab7b", "title": "Internal IP Address leak in Misconfigured WordPress to bypass WAF", "url": "https://eval.blog/research/internal-ip-address-leak-in-misconfigured-wordpress-to-bypass-waf/", "published_at": "2020-12-26T23:46:46+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba114395dcff", "title": "You don’t need xss.rocks/xss.js", "url": "https://eval.blog/blog/you-dont-need-xss-rocks-xss-js/", "published_at": "2020-12-26T23:06:28+00:00" }, { "id": "01a0cf91-7ce6-710e-9261-a9246ab58e6b", "title": null, "url": "https://eval.blog/categories/security/", "published_at": "2020-12-26T23:06:28+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba11446c64fa", "title": "Dynamic importing stuff in Python", "url": "https://eval.blog/blog/dynamic-importing-stuff-in-python/", "published_at": "2020-06-08T23:21:10+00:00" }, { "id": "01a08775-9bf4-7090-aea8-ba1145025799", "title": "Public Vulnerability Reports without CVEs", "url": "https://eval.blog/cves/bug-bounty-reports/", "published_at": null }, { "id": "01a0cf91-7ce6-710e-9261-a9246ceb15b7", "title": null, "url": "https://eval.blog/books/", "published_at": null }, { "id": "01a0cf91-7ce6-710e-9261-a9246d8c73dc", "title": null, "url": "https://eval.blog/categories/books/", "published_at": null }, { "id": "01a0cf91-7ce6-710e-9261-a9246e60bd07", "title": null, "url": "https://eval.blog/tags/", "published_at": null } ] posts Claim your blog
Back to eval.blog
Blog · corpus.blog/blogs/eval.blog/posts

eval.blog

eval.blog

2026

2025

2024

2023

2021

2020

Undated