HieuPenguinnn Blog
Home CVE Write-up About
Home
CVE
Write-up
About
Type a keyword to search posts
HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

TJCTF2026-web/paper-trail CVE-2026-59557 - Events Made Easy Arbitrary Person Record Modification Without Login GPNCTF2026-Fancy Food Notifications Approve Please, Genie! CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API

PTITCTF Quals 2026 (7 challenges)

PTITCTF Quals 2026

Approve Please, Genie!

CSS injection and browser side-channel exfiltration leak the flag from the approval bot.

Read
CTF Web CSS Injection Side Channel PTITCTF
PTITCTF Quals 2026

Brain Rot

Vite CVE-2025-30208 bypasses the dev server allow list and exposes arbitrary files through /@fs/.

Read
CTF Web Vite CVE-2025-30208 PTITCTF
PTITCTF Quals 2026

Độ Mixi

DOM Clobbering bypasses the sanitizer and enables file-name disclosure followed by flag read.

Read
CTF Web DOM Clobbering Local File Read PTITCTF
PTITCTF Quals 2026

LEMON MELON COOKIE

Client-side privilege escalation and SQL injection lead to the administrator account and flag.

Read
CTF Web SQL Injection Privilege Escalation PTITCTF
PTITCTF Quals 2026

Machine Love

Double URL encoding bypasses an absolute-path filter and enables local file read.

Read
CTF Web Path Traversal Local File Read PTITCTF
PTITCTF Quals 2026

Palworld Mod

Path traversal in the mod build flow writes a Python codec payload and reaches server-side code execution.

Read
CTF Web Path Traversal RCE PTITCTF
PTITCTF Quals 2026

PTIT Portfolio Renderer

Jinja2 SSTI bypasses a blacklist, reaches RCE, and reads the challenge flag.

Read
CTF Web SSTI RCE PTITCTF
HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

Machine Love OmniCTF2026-web/Ganzir UMassCTF2026-Brick by Brick GPNCTF2026-cookoff CVE-2026-57365 - Stored XSS in reCAPTCHA for Asgaros Forum via Site Key
10 CVE 31 CTF writeups 41 posts
© 2026 HieuPenguinnn | Powered by Astro & Tailwind | Theme by santisify
Home CVE Write-up About