content-type

1 article
sort: new top best
clear filter
0 4/10
bug-bounty

A researcher documents discovering multiple MIME sniffing-dependent XSS vulnerabilities at Google by exploiting improper Content-Type headers and missing X-Content-Type-Options: nosniff headers, earning thousands in bounties while exploring how browsers may interpret non-HTML content as executable code.

Google KomodoSec
komodosec.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details