<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PwnFuzz Labs</title><description>Cutting-edge research, technical writeups, and exploit development from the PwnFuzz team.</description><link>https://pwnfuzz.github.io/</link><item><title>The Cryptographic Blind Spot: Sante PACS Server&apos;s Decryption Overflow Unveiled</title><link>https://pwnfuzz.github.io/posts/sante-pacs-cve-2025-2263-buffer-overflow/</link><guid isPermaLink="true">https://pwnfuzz.github.io/posts/sante-pacs-cve-2025-2263-buffer-overflow/</guid><description>This article contains a full breakdown of a stack-based buffer overflow vulnerability found in Sante PACS Server version before 4.2.0 (Credits: Tenable Research). The whole application is built on top of the C, meaning we will deal with full reverse engineering, IDA pseudocode, disassemblers and debugger shenanigans.</description><pubDate>Mon, 21 Jul 2025 00:00:00 GMT</pubDate><author>D4mianWayne</author></item><item><title>CVE 2025-2825 - CrushFTP Authentication Bypass Analysis</title><link>https://pwnfuzz.github.io/posts/crushftp-cve-2025-2825/</link><guid isPermaLink="true">https://pwnfuzz.github.io/posts/crushftp-cve-2025-2825/</guid><description>Comprehensive analysis of CVE-2025-2825, a critical authentication bypass vulnerability in CrushFTP. Technical deep dive into the root cause of the vulnerability, patch analysis and exploitation process.</description><pubDate>Sun, 30 Mar 2025 00:00:00 GMT</pubDate><author>D4mianWayne</author></item><item><title>CVE 2024-37397 - Ivanti Endpoint Manager XXE Vulnerability</title><link>https://pwnfuzz.github.io/posts/ivanti-endpoint-manager-xxe-cve-2024-37397/</link><guid isPermaLink="true">https://pwnfuzz.github.io/posts/ivanti-endpoint-manager-xxe-cve-2024-37397/</guid><description>This blog provides an in-depth analysis of the exploitation process for an unauthenticated External XML Entity (XXE) vulnerability in Ivanti Endpoint Manager, identified as CVE-2024-37397.</description><pubDate>Sun, 24 Nov 2024 00:00:00 GMT</pubDate><author>D4mianWayne</author></item><item><title>Exploring Recent CVEs in HPE Insight Remote Support</title><link>https://pwnfuzz.github.io/posts/hpe-irs-cve-deep-dive/</link><guid isPermaLink="true">https://pwnfuzz.github.io/posts/hpe-irs-cve-deep-dive/</guid><description>In this post, we’ll delve into two vulnerabilities recently discovered in the HPE Insight Remote Support (IRS) application, versions prior to v7.14.0.629. These vulnerabilities—CVE-2024-53675 (unauthenticated XXE vulnerability) and CVE-2024-53676 (Remote Code Execution, or RCE vulnerability)—pose significant security risks, allowing unauthorized access and arbitrary code execution on vulnerable systems.</description><pubDate>Wed, 08 Jan 2025 00:00:00 GMT</pubDate><author>D4mianWayne</author></item><item><title>CVE 2024-4040 - CrushFTP Server-Side Template Injection Vulnerability Analysis</title><link>https://pwnfuzz.github.io/posts/crushftp-cve-2024-4040/</link><guid isPermaLink="true">https://pwnfuzz.github.io/posts/crushftp-cve-2024-4040/</guid><description>This blog post contains a thorough analysis of Server Side Template Injection vulnerability in a commercial Managed File Transfer product named CrushFTP. Exploit script is available.</description><pubDate>Thu, 09 May 2024 00:00:00 GMT</pubDate><author>D4mianWayne</author></item></channel></rss>