chaining

2 articles
sort: new top best
clear filter
0 2/10

A lab-based case study demonstrating the chaining of SQL injection vulnerabilities into remote code execution through privilege escalation techniques.

medium.com · Shatha511 · 12 hours ago · details
0 8/10

Security researchers discovered an SSRF vulnerability on Airbnb's chat endpoint by chaining a third-party open redirect in LivePerson's API with path traversal via encoded backslashes, enabling arbitrary requests from the Airbnb server. The attack exploited LivePerson's visitorWantsToChat redirect parameter and path parameter traversal to bypass intended API boundaries.

Airbnb LivePerson Ben Sadeghipour Brett Buerhaus
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details