content-type-header

2 articles
sort: new top best
clear filter
0 5/10

Researcher exploited CVE-2017-5638 (Apache Struts2 RCE) in a Yahoo application by discovering a vulnerable .do endpoint and bypassing the WAF using a specially crafted Content-Type header payload, earning a $5,500 bounty from Yahoo through HackerOne.

CVE-2017-5638 Apache Struts2 Yahoo Selligent Messages Studio HackerOne Th3G3nt3lman
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 7 hours ago · details
0 7/10

A stored XSS vulnerability in InternShala.com exploited through a JSON endpoint with incorrect text/html content-type header. The attacker bypassed multiple filters (whitespace, forward slashes, alert/prompt functions, parentheses, angle brackets) using character substitution and URL encoding to inject a working XSS payload via the current_city_administrative_area_level_2 parameter.

InternShala.com Noman Shaikh
bugbaba.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 7 hours ago · details