poc

5 articles
sort: new top best
clear filter
0 6/10

CVE-2024-50379 is a critical TOCTOU race condition in Apache Tomcat's JSP compilation that enables remote code execution on case-insensitive file systems when the default servlet is misconfigured with write permissions enabled. The article provides a technical POC demonstrating exploitation by uploading benign and malicious JSP files that differ only in case (file.jsp vs FILE.JSP) on Windows systems.

CVE-2024-50379 Apache Tomcat Vidhi patel Freedium
infosecwriteups.com · Vidhi patel · 2 hours ago · details
0 5/10

A CORS misconfiguration on api.artsy.net allowed attackers to exfiltrate sensitive user data (email, phone, authentication tokens, etc.) by crafting a malicious webpage that leverages the overly permissive Access-Control-Allow-Credentials and Access-Control-Allow-Origin headers to make cross-origin requests with victim credentials.

api.artsy.net Muhammad Khizer Javed
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

A subdomain takeover vulnerability was discovered on live.lamborghini.com where an expired CloudFront distribution CNAME allowed an attacker to claim the subdomain by creating their own AWS S3 bucket and CloudFront distribution. The researcher demonstrated the attack by registering the subdomain and uploading malicious content, highlighting the risk of phishing and impersonation attacks.

Lamborghini live.lamborghini.com AWS CloudFront S3 Muhammad Khizer Javed
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 6/10

CVE-2017-5244 is a CSRF vulnerability in Metasploit commercial editions (Express, Community, Pro <4.14.0) where GET requests to stop/stop_all task routes were not properly validated, allowing attackers to kill all running Metasploit tasks via malicious JavaScript injection. The vulnerability exploited missing CSRF token validation and improper HTTP method enforcement.

CVE-2017-5244 Metasploit Project Rapid7 Mohamed A. Baset Seekurity Samuel Huckins
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 5/10

A researcher chained a CSRF vulnerability with a stored XSS flaw to create persistent XSS attacks. By leveraging missing CSRF protection on a template creation endpoint and exploiting HTML/SVG injection in description fields, an attacker could trick victims into creating malicious templates that execute JavaScript when viewed.

Mohamed Sayed
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details