third-party-service

2 articles
sort: new top best
clear filter
0 6/10

A subdomain takeover vulnerability was discovered on flock.co where the subdomain newdev.flock.co had a CNAME record pointing to readme.io's infrastructure, but the custom domain was never claimed in readme.io's project settings, allowing an attacker to register a readme.io account and claim ownership of the vulnerable subdomain.

flock.com flock.co newdev.flock.co readme.io cname.readme.io
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 3/10
bug-bounty

A stored XSS vulnerability was discovered on survey.dropbox.com, which was a CNAME pointing to mysurveylab.com. The third-party survey platform's forms were vulnerable to XSS, allowing attackers to inject malicious scripts accessible through the Dropbox subdomain for potential phishing attacks.

Dropbox survey.dropbox.com mysurveylab.com Kumar
kumar.ninja · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details