payload-engineering

1 article
sort: new top best
clear filter
0 6/10

A researcher exploited a blind XSS vulnerability in a backend portal by iteratively bypassing WAF filters through payload modification, ultimately achieving code execution and cookie exfiltration using an img tag with onload handler that extracts document.cookie to a logging endpoint.

blindf.com Dirtycoder
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details