Blog Archive | Tağmaç - root@Tagoletta:~#

Blog Archive

All Posts

Single-Packet Race Condition: Sub-Millisecond Web Exploitation
Wed May 27 2026

How the single-packet attack technique eliminates network jitter to exploit sub-millisecond race conditions in web applications — and how CVE-2024-58248 in nopCommerce was exploited using Burp Suite.

Category: Security Research
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server
Wed May 27 2026

How Orange Tsai's Confusion Attacks exploit URL decoding inconsistencies across Apache modules to chain ACL bypass, SSRF, and unauthenticated RCE — #1 web hacking technique of 2024.

Category: Security Research
CVE-2025-69460 – Simple Image Gallery 1.0 - Remote Code Execution (Unauthenticated)
Wed Jan 21 2026

CVE-2025-69460: Unauthenticated Remote Code Execution (RCE) vulnerability in Simple Image Gallery 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Category: Security Research
CVE-2025-69457 – Responsive Tourism Website 3.1 - Remote Code Execution (Unauthenticated)
Wed Jan 21 2026

CVE-2025-69457: Unauthenticated Remote Code Execution (RCE) vulnerability in Responsive Tourism Website 3.1. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Category: Security Research
CVE-2023-38890 – Online Shopping Portal 3.1 Remote Code Execution
Wed Jan 21 2026

CVE-2023-38890: Unauthenticated SQL Injection to Remote Code Execution (RCE) vulnerability in Online Shopping Portal 3.1. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Category: Security Research
CVE-2025-69458 – Movie Rating System 1.0 - SQL Injection to RCE (Unauthenticated)
Wed Jan 21 2026

CVE-2025-69458: Unauthenticated SQL Injection to Remote Code Execution (RCE) vulnerability in Movie Rating System 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Category: Security Research
CVE-2025-69459 – Movie Rating System 1.0 - Broken Access Control
Wed Jan 21 2026

CVE-2025-69459: Broken Access Control vulnerability allowing Admin Account Creation in Movie Rating System 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.

Category: Security Research
Building a Compact Cyber Security Home Lab with Proxmox
Mon Dec 08 2025

Turning a modest notebook into a powerhouse running Tor, Exploit Dev, Docker, and OPNsense environments.

Category: Research
Traffic Offense Management System 1.0 - Remote Code Execution (Unauthenticated)
Wed Aug 18 2021

Zero-Day Discovery & Exploit Development: unauthenticated SQL Injection to RCE in Traffic Offense Management System 1.0. Full writeup with PoC exploit code by Tağmaç 'Tagoletta'.

Category: Security Research