Web Hack List

Preliminary research

cPanel file read through SMTP-created paths and CalDAV parser collisions

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Uses SMTP plus-address delivery to create a Maildir path required by a CalDAV attachment route. Later decoding and traversal expose another file, while an unretained privilege-reduction object restores elevated access too early; the chain combines cross-protocol filesystem preparation with path and object-lifetime mistakes.

Record

Researcher
Shubham Shah and Adam Kues
Published by
Searchlight Cyber

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Shubham Shah and Adam Kues, first published at the original source. Preserved copies are kept so the citation survives its host.