https://www.banphotphisai.go.th/yuki.htm notified by Senzawa
>> AUTHOR: deepcore
https://www.banphotphisai.go.th/yuki.htm notified by Senzawa
http://kaengkhro.go.th/yuki.htm notified by Senzawa
https://dptdds.dpt.go.th/yuki.htm notified by Senzawa
http://taxpak10.excise.go.th/yuki.htm notified by Senzawa
http://kingrama10.dol.go.th/sad.htm notified by Senzawa
A brief write up discussing disclosure of internal IPs and hostnames from Apple bots leveraging Via and X-Forwarded-For headers.
Lot Reservation Management System 1.0 – Authentication Bypass
Gym Management System 1.0 – ‘id’ SQL Injection
Lot Reservation Management System 1.0 – Cross-Site Scripting (Stored)
School Faculty Scheduling System 1.0 – ‘id’ SQL Injection