http-header-injection

2 articles
sort: new top best
clear filter
0 7/10

A step-by-step walkthrough of exploiting boolean-based SQL injection through the User-Agent HTTP header to enumerate database version, table names, column names, and extract user credentials from a MariaDB database.

fr0stNuLL MySQL MariaDB Oracle MicrosoftSQL
medium.com · kh4sh3i/bug-bounty-writeups · 20 hours ago · details
0 7/10

A bug bounty hunter discovered a stored XSS vulnerability in a Drupal application by chaining cache poisoning with an unreflected HTTP header (style) discovered via Param Miner brute-forcing, allowing arbitrary XSS payloads to be cached and served to all users visiting a poisoned URL.

Rohan Aggarwal Drupal Rails Param Miner Burp Suite HackerOne Zend X-Original-URL X-Rewrite-URL
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details