xss-filter-bypass

2 articles
sort: new top best
clear filter
0 7/10

Reflected XSS vulnerability in Tokopedia train ticket search exploited by splitting a closing script tag across two parameters (ori and dest) to bypass server-side filtering that only blocked <.*> patterns within a single parameter. The XSS payload allowed extraction of the session cookie despite HTTP-only flag due to accidental exposure in a JavaScript variable.

Tokopedia tokopedia train ticket _SID_Tokopedia Chrome XSS auditor Firefox CVE-2019-19502
visat.me · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 7/10

XSS vulnerability in Facebook Studio discovered via incorrect Content-Type header (text/html instead of application/json) that allowed malicious JavaScript to bypass client-side escaping and XSS filters by exploiting content-type sniffing behavior. The vulnerability was fixed by correcting the Content-Type header to application/json.

Facebook Studio Facebook Chrome XSS Auditor IE XSS Filter Jack
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details