<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://fatihhcelik.github.io/posts/CLEAR-TEXT-PASSWORD-NETIS-DL4323-CVE-2019-20074/</loc>
<lastmod>2019-12-24T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-Login-Page-Configuration-RCE-CVE-2020-11815/</loc>
<lastmod>2020-01-04T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Qdpm-Web-Based-Project-Management-Software-RCE-CVE-2020-11811/</loc>
<lastmod>2020-01-14T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-CSRF-Bypass-Account-Takeover-CVE-2020-11818/</loc>
<lastmod>2020-01-14T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-Maintenance-Mode-Configuration-RCE-CVE-2020-11817/</loc>
<lastmod>2020-01-14T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-RCE-Local-File-Inclusion-CVE-2020-11819/</loc>
<lastmod>2020-01-14T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-SQL-Injection-entities_id-CVE-2020-11820/</loc>
<lastmod>2020-01-15T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-SQL-Injection-filters-0-value-(POST)-CVE-2020-11812/</loc>
<lastmod>2020-01-15T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-SQL-Injection-filters-1-value-(POST)-CVE-2020-11812/</loc>
<lastmod>2020-01-15T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Rukovoditel-SQL-Injection-reports_id-(POST)-CVE-2020-11816/</loc>
<lastmod>2020-01-15T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Memono-Insecure-Data-Storage-IOS-CVE-2020-11826/</loc>
<lastmod>2020-02-23T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Virtualbox-Local-DOS-Vulnerability-CVE-2020-2909/</loc>
<lastmod>2020-04-14T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/GOG-Galaxy-Desktop-App-Local-Privilege-Escalation-CVE-2020-11827/</loc>
<lastmod>2020-06-04T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Starting-The-CrackMe-Series-Why/</loc>
<lastmod>2020-08-09T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/The-First-CrackMe-of-The-Series-CrackMe1/</loc>
<lastmod>2021-03-05T20:05:46+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/CMSUno-1.6.2-RCE-Authenticated-(config.php)-CVE-2020-25538/</loc>
<lastmod>2020-09-30T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/CMSUno-1.6.2-RCE-Authenticated-(password.php)-CVE-2020-25557/</loc>
<lastmod>2020-09-30T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Sentrifugo-3.2-RCE-Authenticated-(announcements)-CVE-2020-26804/</loc>
<lastmod>2020-10-06T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Sentrifugo-3.2-RCE-Authenticated-(assets)-CVE-2020-26803/</loc>
<lastmod>2020-10-06T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Sentrifugo-3.2-SQLi-employeeNumId-parameter-CVE-2020-26805/</loc>
<lastmod>2020-10-06T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Group-Office-CRM-SSRF/</loc>
<lastmod>2020-12-10T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Group-Office-CRM-Stored-XSS-via-SVG-File/</loc>
<lastmod>2020-12-10T11:33:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Insecure-Yaml-Deserialization/</loc>
<lastmod>2021-12-12T11:34:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Missing-IP-Address-Control-in-isPublic()-Function-Leads-to-SSRF-Bypass-PoC/</loc>
<lastmod>2024-03-02T05:51:35+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/Crashing-Python-http.client-CVE-2025-13836/</loc>
<lastmod>2025-12-18T05:00:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/n8n-OS-command-inj/</loc>
<lastmod>2026-02-09T04:25:54+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/</loc>
<lastmod>2026-02-09T04:25:54+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/n8n-cve-2026-27498/</loc>
<lastmod>2026-02-25T22:43:40+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/posts/gitleaks-abusing-sprig-for-exfiltration/</loc>
<lastmod>2026-03-25T18:00:00+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/categories/</loc>
<lastmod>2026-03-26T01:44:59+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/tags/</loc>
<lastmod>2026-03-26T01:44:59+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/archives/</loc>
<lastmod>2026-03-26T01:44:59+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/advisories/</loc>
<lastmod>2026-03-26T01:44:59+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/hall-of-fame/</loc>
<lastmod>2026-03-26T01:44:59+08:00</lastmod>
</url>
<url>
<loc>https://fatihhcelik.github.io/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/tags/vulnerability-research/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/tags/reverse-engineering/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/categories/vulnerability-research/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/categories/reverse-engineering/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/categories/crackme/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/page2/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/page3/</loc>
</url>
<url>
<loc>https://fatihhcelik.github.io/googled33344826291559b.html</loc>
<lastmod>2026-03-26T01:44:36+08:00</lastmod>
</url>
</urlset>
