xss

316 articles
Sort: New Top Best
clear filter
0 9/10

A multi-stage vulnerability in GitHub's private pages authentication flow combining CRLF injection, null byte parsing bypass, and cookie prefix case-sensitivity to achieve XSS and cache poisoning on private organization pages. The attack exploited case-insensitive cookie handling to bypass __Host- prefix protections and nonce fixation to achieve unauthenticated arbitrary code execution.

GitHub HackerOne ginkoid $35,000 bounty github.io pages-auth.github.com
robertchen.cc · kh4sh3i/bug-bounty-writeups · 3 hours ago · details
0
10degres.net · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0

A researcher exploited CORS misconfiguration combined with reflected XSS on a Netgear subdomain to extract sensitive user data (email, age, gender, DOB) by sending malicious links that executed JavaScript in the attacker's context and exfiltrated API responses. The vulnerability required an endpoint that accepted subdomain origins and an XSS vulnerability on a whitelisted subdomain to execute the data theft payload.

Netgear Bugcrowd James Kettle Daniel Bakker Kaushal Parikh Noman Shaikh
bugbaba.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0

A researcher discovered a Server-Side Request Forgery (SSRF) vulnerability in Google Sites' Caja server that allowed fetching arbitrary resources from Google's internal Borg cluster management network, exposing sensitive information about internal infrastructure including job details, system users, and resource allocation. The vulnerability was reported to Google's VRP and patched within 48 hours.

Google Google Sites Google Caja Google App Engine Borg Kubernetes Gvisor Google VRP MapReduce BitTable Flume GFS
opnsec.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
bugbaba.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
xss
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
More