url-manipulation

2 articles
sort: new top best
clear filter
0 7/10

A critical CSRF bypass vulnerability in Facebook's ads management interface where the fb_dtsg token validation could be circumvented by manipulating the show_dialog_uri parameter and using double-encoding (%253F) to bypass the initial fix, allowing arbitrary account modifications like email changes and security setting alterations without proper CSRF protection.

Facebook Pouya OWASP
blog.darabi.me · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 5/10

A stored XSS vulnerability was discovered in Google Custom Search Engine's promotion URL feature, where javascript: protocol handlers were not filtered, allowing attackers to inject malicious URLs that execute when victims click promoted results.

Google Custom Search Engine cse.google.com Sreeram
thesecurityexperts.wordpress.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details