HieuPenguinnn Blog
Home CVE Write-up About
Home
CVE
Write-up
About
Type a keyword to search posts
HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

UTCTF2026-Time to Pretend OmniCTF2026-web/StayWild GPNCTF2026-recipeloader CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API CVE-2026-57408 - Peach Payments Gateway Payment Status Forgery via Unauthenticated Webhook

Tag: PTITCTF (7 posts)

A
PTITCTF Quals 2026

Approve Please, Genie!

CSS injection and browser side-channel exfiltration leak the flag from the approval bot.

Read
CTF Web CSS Injection Side Channel PTITCTF
B
PTITCTF Quals 2026

Brain Rot

Vite CVE-2025-30208 bypasses the dev server allow list and exposes arbitrary files through /@fs/.

Read
CTF Web Vite CVE-2025-30208 PTITCTF
Đ
PTITCTF Quals 2026

Độ Mixi

DOM Clobbering bypasses the sanitizer and enables file-name disclosure followed by flag read.

Read
CTF Web DOM Clobbering Local File Read PTITCTF
L
PTITCTF Quals 2026

LEMON MELON COOKIE

Client-side privilege escalation and SQL injection lead to the administrator account and flag.

Read
CTF Web SQL Injection Privilege Escalation PTITCTF
M
PTITCTF Quals 2026

Machine Love

Double URL encoding bypasses an absolute-path filter and enables local file read.

Read
CTF Web Path Traversal Local File Read PTITCTF
P
PTITCTF Quals 2026

Palworld Mod

Path traversal in the mod build flow writes a Python codec payload and reaches server-side code execution.

Read
CTF Web Path Traversal RCE PTITCTF
P
PTITCTF Quals 2026

PTIT Portfolio Renderer

Jinja2 SSTI bypasses a blacklist, reaches RCE, and reads the challenge flag.

Read
CTF Web SSTI RCE PTITCTF
HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

CVE-2026-57341 - Colissimo Officiel Unauthenticated Shipping Rate Tampering LEMON MELON COOKIE TJCTF2026-web/paper-trail UMassCTF2026-Brick by Brick GPNCTF2026-Fancy Food Notifications
10 CVE 31 CTF writeups 41 posts
© 2026 HieuPenguinnn | Powered by Astro & Tailwind | Theme by santisify
Home CVE Write-up About