whitelist-bypass

2 articles
sort: new top best
clear filter
0 8/10

Multiple DOM-based XSS vulnerabilities discovered in iframe buster implementations from major ad tech vendors (Adform, Eyeblaster, Adtech) due to weak regex and whitelist validation on user-controlled parameters, allowing attackers to inject arbitrary JavaScript on top-tier publisher sites.

Randy Westergren Adform Eyeblaster Adtech Google DoubleClick CNN Fandango Forbes
randywestergren.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

The author discovered an XSS vulnerability by bypassing a whitelist-protected redirect parameter through HTTP parameter pollution, combining javascript:// scheme manipulation with multiple 'dest' parameters to execute arbitrary JavaScript code.

Mo'men Basel
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details