<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Ayoub ELMOKHTAR</title><description>Senior Offensive Security Engineer — vulnerability research and security writeups.</description><link>https://ayoubmokhtar.com/</link><item><title>CVE-2024-34716 – The Deceptive PNG Trap: Breaking Down the PNG-Driven Chain from XSS to Remote Code Execution on PrestaShop (&lt;=8.1.5)</title><link>https://ayoubmokhtar.com/post/png_driven_chain_xss_to_remote_code_execution_prestashop_8.1.5_cve-2024-34716/</link><guid isPermaLink="true">https://ayoubmokhtar.com/post/png_driven_chain_xss_to_remote_code_execution_prestashop_8.1.5_cve-2024-34716/</guid><description>A chained XSS-to-RCE vulnerability in PrestaShop (&lt;=8.1.5) exploiting improper file handling to achieve remote code execution via a malicious PNG attachment.</description><pubDate>Fri, 12 Apr 2024 00:00:00 GMT</pubDate></item><item><title>CVE-2024-3116 – Remote Code Execution Vulnerability in pgAdmin - PostgreSQL Tools (&lt;=8.4): Detailed Analysis Report</title><link>https://ayoubmokhtar.com/post/remote_code_execution_pgadmin_8.4-cve-2024-3116/</link><guid isPermaLink="true">https://ayoubmokhtar.com/post/remote_code_execution_pgadmin_8.4-cve-2024-3116/</guid><description>A critical RCE vulnerability in pgAdmin (&lt;=8.4) caused by inadequate validation of file paths, enabling unauthorized code execution on Windows platforms.</description><pubDate>Sun, 31 Mar 2024 00:00:00 GMT</pubDate></item><item><title>CVE-2020-9915 – Failure to properly process form-action &apos;self&apos; leads to CSP bypass in Safari</title><link>https://ayoubmokhtar.com/post/csp-bypass-cve-2020-9915/</link><guid isPermaLink="true">https://ayoubmokhtar.com/post/csp-bypass-cve-2020-9915/</guid><description>Safari failed to enforce the CSP form-action &apos;self&apos; directive, allowing CSRF token exfiltration to attacker-controlled servers.</description><pubDate>Sat, 18 Sep 2021 00:00:00 GMT</pubDate></item><item><title>I could&apos;ve deleted all SMC messages using Brute Force Technique – PayPal</title><link>https://ayoubmokhtar.com/post/paypal-bbp-i-couldve-deleted-all-smc-messages-using-brute-force-technique/</link><guid isPermaLink="true">https://ayoubmokhtar.com/post/paypal-bbp-i-couldve-deleted-all-smc-messages-using-brute-force-technique/</guid><description>A CSRF vulnerability in PayPal&apos;s Message Center allowed brute-forcing message IDs to delete all messages in a victim&apos;s inbox without their knowledge.</description><pubDate>Mon, 23 Apr 2018 00:00:00 GMT</pubDate></item></channel></rss>