referrer-header

1 article
sort: new top best
clear filter
0 6/10
bug-bounty

Three case studies of reflected XSS vulnerabilities discovered on Synack: (1) XSS via javascript: protocol in a referrer parameter, (2) XSS via improper output encoding in account details form fields, and (3) XSS via unfiltered email parameter in password recovery page. Each demonstrates different exploitation vectors and input validation bypasses.

Gaurav Narwani Synack example.com brutelogic _zulln
gauravnarwani.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details