unicode-encoding

2 articles
sort: new top best
clear filter
0 8/10

A detailed walkthrough of exploiting a blind SQL injection vulnerability in a JSON-RPC API by leveraging an IN() clause to infer boolean results through asset count variations, and bypassing WAF filters using Unicode escape sequences to extract database information.

TomNomNom MySQL
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details
0 6/10

Researcher discovered a reflected XSS vulnerability in Zomato's OAuth2 authentication endpoint by enumerating subdomains, finding that user input was reflected without proper sanitization. The XSS was bypassed using a marquee tag with onfinish handler and unicode-encoded confirm() function to evade WAF filters.

Zomato Sudhanshu Rajbhar secretx.zomato.com auth2.zomato.com Hydra Somdev Prateek Tiwari CVE (HackerOne #456333)
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details