google-scholar

1 article
sort: new top best
clear filter
0 8/10

A detailed technical writeup of discovering and exploiting polymorphic image-based XSS vulnerabilities on Google Scholar by embedding JavaScript payloads in JPEG/PNG metadata and entropy-coded segments that survive image processing transformations. The author developed techniques to bypass Google's image reprocessing backend and created a test suite for image library behavior analysis.

Google Scholar Doyensec Lorenzo Stella ImageMagick GraphicsMagick Libvips Exiftool doyensec/StandardizedImageProcessingTest CVE-2023-21800
blog.doyensec.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details