database-credentials

1 article
sort: new top best
clear filter
0 7/10

A researcher bypassed file upload restrictions on a crypto trading platform by manipulating Content-Type headers, uploaded a PHP shell for RCE, extracted database credentials, and gained the ability to modify user account balances, resulting in a P1 severity rating.

Mohammed Abdul Raheem Muhammad Khizer Javed HackerOne OWASP Burp Suite c99 shell
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details