أبحاث أمنية
أبحاث الثغرات الأمنية ومقالات الإفصاح المنسق عنها.
Command Injection
How an incomplete security fix in Coolify left 5 credential fields injectable in database backup commands, allowing root-level RCE on all managed servers.
Account Takeover
Static MD5 auth tokens, unrestricted .htaccess uploads, and four unsafe unserialize() calls chain together for full server compromise.