web-crawler

1 article
sort: new top best
clear filter
0 7/10

Googlebot, based on Chrome 41, lacks XSS protection and executes JavaScript in URLs, allowing attackers to inject malicious content, manipulate search index directives (canonicals), inject links that are crawled and indexed, and ultimately manipulate PageRank and search rankings. The researcher disclosed this zero-day to Google in November 2018, which remained unpatched as of publication.

Googlebot Google Chrome 41 Tom Anthony Distilled Robin Lord Revolut Google Mobile Friendly Tool Google Website Rendering Service (WRS) Google URL Inspector Tool Sam Nemzer Joel Mesherghi OpenBugBounty Majestic Million
tomanthony.co.uk · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details