cookie-signing

1 article
sort: new top best
clear filter
0 6/10

Researcher discovered RCE via exposed Rails secret token leaked through Rack's ShowExceptions error page enabled on production. By fuzzing the filename parameter with %0d to trigger an exception, they obtained the secret_token used to sign cookies, which they then exploited to achieve remote code execution across two in-scope assets.

Rack Rails ShowExceptions action_dispatch.secret_token
sites.google.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details