whitehat

2 articles
sort: new top best
clear filter
0 3/10
vulnerability-research

Merkle Bonsai's blog aggregates multiple smart contract vulnerability case studies, including findings in Oasys (an Ethereum L2 for gaming), Eco's lockup contracts, and Ocean Protocol's hybrid NFT implementation, demonstrating design flaws where on-chain data reliance creates exploitable attack surfaces.

Oasys Ethereum Bandai Namco DoubleJump.japan Immunefi Eco Ocean Protocol Merkle Bonsai
mirror.xyz · merkle_bonsai · 23 hours ago · details
0 6/10

A reflected XSS vulnerability discovered in eBay's search parameter (LH_SpecificSeller) that bypassed character filters (<, >, comma) by leveraging CSS expression payloads in Internet Explorer. The exploit worked despite the vulnerable code being inside a display:none span by using style="xss:expression()" to execute arbitrary JavaScript.

eBay Sukhmeet Singh Internet Explorer
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details