Blog Logo
Sebastian Neef - 0day.work

  • Home
  • Contact
  • @0daywork
  • @gehaxelt
  • Impressum
  • Datenschutz

Sebastian Neef

53 posts

CVE-2023-6294: popup-builder <= 4.2.6 Admin+ SSRF & File Read

31 January 2024  cve

In this blog post I'll describe the details of CVE-2023-6294, a local file inclusion in WordPress' popup-builder plugin.

CVE-2023-6295: so-widgets-bundle < 1.51.0 - Admin+ Local File Inclusion

12 December 2023  cve

In this blog post I'll describe the details of CVE-2023-6295, a local file inclusion in WordPress' so-widgets-bundle plugin.

Measuring a Tor Hidden Service's idle Traffic

19 November 2020  research

A month ago, I wondered myself how much traffic an idle hidden service would consume just to keep the necessary circuits open. To answer this question, I set up a

BalCCon2k20 CTF: Let Me See And Dawsonite Writeups

28 September 2020  writeups

Last weekend, I had the time to play the BalCCon2k20 CTF [https://ctftime.org/event/1100] and since there are no writeups for the last two web challenges yet, I

Credentials hiding in plain sight or how I pwned your http auth

05 July 2020  research

In this blog post I will go over the little research project I did about http authentication credentials hiding in plain sight. Idea A few month ago, I was thinking

Page 1 of 11 Older Posts →
© 2025 Sebastian Neef - 0day.work All rights reserved.

Coder Ghost Theme created by Milos Bejda
Proudly published with Ghost