backend-exploitation

1 article
sort: new top best
clear filter
0 6/10

A bug bounty researcher discovered LDAP injection vulnerability in a registration form while attempting blind XSS exploitation. The server was passing unsanitized user input directly to LDAP directory operations, revealed through error messages about invalid directory pathnames.

XSS Hunter The WebApplication Hacker's Handbook Davide Tampellini
nc-lp.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details