bug-bounty497
google349
xss301
microsoft291
facebook262
rce211
exploit198
malware168
apple161
cve135
account-takeover115
bragging-post102
privilege-escalation96
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering54
react52
access-control52
input-validation49
cross-site-scripting48
cloudflare47
aws47
docker46
lfi46
web-security46
sql-injection45
smart-contract45
web-application44
ethereum44
web343
oauth43
defi43
ctf43
node42
open-source39
race-condition39
pentest39
cloud37
idor37
info-disclosure36
burp-suite36
auth-bypass35
0
8/10
vulnerability
Technical writeup demonstrating how arbitrary XSS vulnerabilities in Outlook and Twitter were exploited by chaining cookie injection attacks with browser-specific parsing differences. The researchers discovered endpoints that reflected user input into Set-Cookie headers, then leveraged Safari's comma-delimited cookie parsing to inject malicious ClientId/session cookies that would execute stored XSS payloads on victim browsers.
xss
cross-site-scripting
cookie-injection
crlf-injection
flash-messages
safari-bypass
set-cookie-header
bug-bounty
outlook
twitter
vulnerability-chaining
csp-bypass
Outlook
Twitter
Safari
Chrome
Firefox
RFC 2109
Ruby on Rails
Microsoft
ActionDispatch::Flash