bing

2 articles
sort: new top best
clear filter
0 5/10

A researcher discovered an SSRF/XSPA vulnerability in Microsoft's Bing Webmaster Central that could be bypassed using the nip.io DNS service to resolve to internal IP addresses (127.127.127.127) and enumerate local ports and administrative directories.

Microsoft Bing Bing Webmaster Central Elber Andre nip.io
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details
0 5/10

A researcher demonstrated how chaining XSS and CSRF vulnerabilities in Bing's beta image favorites feature could compromise user accounts. The attack exploited missing CSRF tokens and lack of X-Requested-With headers, combined with javascript: protocol injection in URL fields, allowing account takeover via a malicious site.

Bing Microsoft Sai Krishna Kothapalli
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details