file-protocol

4 articles
sort: new top best
clear filter
0 6/10

A researcher discovered an SSRF vulnerability leading to local file disclosure by bypassing URL validation filters. The application rejected file:/// payloads but accepted file:// with a single path component (file://s/etc/passwd), allowing arbitrary local file access through a simulated browser feature.

Tung Pun Hackerone requestb.in Chrome/60.0.3112.101
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 2/10
bug-bounty

A Local File Inclusion (LFI) vulnerability was discovered in Nokia Maps that allowed reading arbitrary files via the file:// protocol (e.g., http://maps.nokia.com/services/file:///etc/passwd). The bug was reported in January 2013 and patched within 18 days.

Nokia Maps Nokia Lumia 920 Shashank
blog.shashank.co · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 8/10

XSS vulnerability in dynamically generated PDF endpoint where unsanitized user input (utrnumber parameter) is rendered as HTML/JavaScript in PDFs, allowing arbitrary JavaScript execution under file:// origin and enabling local file read via XMLHttpRequest to access /etc/passwd.

Rahul Maini Bugcrowd xyz.com
noob.ninja · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 8/10

A researcher escalated XSS in a PhantomJS image rendering endpoint to arbitrary local file read by exploiting JavaScript execution in the file:// context, using document.write to force synchronization and XMLHttpRequest to exfiltrate files from the Lambda environment at /var/task/.

PhantomJS AWS Lambda Brett (researcher name - ziot)
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details