elmah

1 article
sort: new top best
clear filter
0 6/10

An SSRF vulnerability was discovered in a PDF generator where the attacker bypassed character filters by exploiting a mobile app to inject an iframe payload using forward-slash spacing, then leveraged DNS rebinding to access internal endpoints like elmah.axd and exfiltrate error logs via the web app's PDF function.

John Michael Mondilla elmah.axd
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details