<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
      <title>EGAD!</title>
      <link>https://egad.attelier.org</link>
      <description>Last 10 notes on EGAD!</description>
      <generator>Quartz -- quartz.jzhao.xyz</generator>
      <item>
    <title>Contributing</title>
    <link>https://egad.attelier.org/CONTRIBUTING</link>
    <guid>https://egad.attelier.org/CONTRIBUTING</guid>
    <description><![CDATA[ Arguing back These are judgment calls. Some of them are wrong. ]]></description>
    <pubDate>Mon, 24 Aug 2026 23:10:50 GMT</pubDate>
  </item><item>
    <title>README</title>
    <link>https://egad.attelier.org/README</link>
    <guid>https://egad.attelier.org/README</guid>
    <description><![CDATA[ 🍂 EGAD! Errata Gathered, Appraised &amp; Documented EGAD! is where Secur0 writes down the CVSS 4.0 calls that aren’t obvious. ]]></description>
    <pubDate>Mon, 24 Aug 2026 23:08:25 GMT</pubDate>
  </item><item>
    <title>idor</title>
    <link>https://egad.attelier.org/access_control/object_level/idor</link>
    <guid>https://egad.attelier.org/access_control/object_level/idor</guid>
    <description><![CDATA[ Insecure Direct Object Reference (IDOR) The application accepts an identifier for an object and acts on it without checking that the caller owns it. ]]></description>
    <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>HTMLi</title>
    <link>https://egad.attelier.org/injection/client_side/HTMLi</link>
    <guid>https://egad.attelier.org/injection/client_side/HTMLi</guid>
    <description><![CDATA[ HTML Injection Attacker-controlled input is interpreted as markup by something that renders it: a page, a mail client, a document generator. ]]></description>
    <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>EGAD!</title>
    <link>https://egad.attelier.org/</link>
    <guid>https://egad.attelier.org/</guid>
    <description><![CDATA[ Errata Gathered, Appraised &amp; Documented How Secur0’s triage team scores the harder CVSS 4.0 calls, one vulnerability class at a time. ]]></description>
    <pubDate>Sun, 12 Jul 2026 23:32:41 GMT</pubDate>
  </item><item>
    <title>xss</title>
    <link>https://egad.attelier.org/injection/client_side/xss</link>
    <guid>https://egad.attelier.org/injection/client_side/xss</guid>
    <description><![CDATA[ Cross-Site Scripting (XSS) Attacker-controlled input is reflected or stored and then executed as script in another user’s browser. ]]></description>
    <pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate>
  </item>
    </channel>
  </rss>