cache-exploitation

1 article
sort: new top best
clear filter
0 7/10

A bug bounty hunter discovered a stored XSS vulnerability in a Drupal application by chaining cache poisoning with an unreflected HTTP header (style) discovered via Param Miner brute-forcing, allowing arbitrary XSS payloads to be cached and served to all users visiting a poisoned URL.

Rohan Aggarwal Drupal Rails Param Miner Burp Suite HackerOne Zend X-Original-URL X-Rewrite-URL
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details