prod-server

1 article
sort: new top best
clear filter
0 6/10

Security researcher discovered an authentication bypass on springboard.google.com that escalated to local file inclusion (LFI) on Google production servers, allowing reading of /proc files with admin privileges. The vulnerability was found through directory enumeration and subsequently patched; the researcher received a $13,337 bounty.

Google VRP springboard.google.com cloudsearch.google.com Omar Espino wfuzz domained masscan SecLists ESCAL8
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details