reflective-xss

2 articles
sort: new top best
clear filter
0 5/10

Security researcher discovered a reflective XSS vulnerability and open redirect flaw on Indeed's offers.indeed.com subdomain via the 'target' URL parameter in a PDF report functionality. The vulnerability allowed arbitrary JavaScript execution and redirection to external sites, which was patched by Indeed within a week.

Indeed.com offers.indeed.com Sublist3r Bugcrowd Syntax Error
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

A CSP bypass vulnerability in Microsoft Edge (CVE-2017-0135) where attackers could abuse the XSS filter's default mode to disable meta-tag-based CSP policies by appending malicious meta elements as URL parameters, causing the filter to neuterase the legitimate CSP declaration and allow script execution.

CVE-2017-0135 MS17-007 Microsoft Edge Internet Explorer 8 Xiaoyin Liu MSRC FreeBuf
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details