character-filtering

1 article
sort: new top best
clear filter
0 5/10

A writeup describing XSS exploitation via cookie injection where character filtering (equals signs, parentheses) was bypassed using script tag injection and backtick encoding techniques. The attacker eventually used a `-prompt\`1\`-` payload to trigger the vulnerability despite WAF restrictions.

GA_countryCode brutelogic akita rahul-maini
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details