-
Stored XSS on LaporBug.id: Injecting Payloads through Profile Images
•
LaporBug.id is a Bug Bounty Platform based in Indonesia. If you want to know more about LaporBug.id, visit…
-
Exploiting %0A Injection for XSS on Samsung
•
I began by searching for subdomains using Sublist3r and then checked the HTTP status codes for each subdomain…
-
POST-based XSS on DomaiNesia
•
DomaiNesia is a company that offers domain registration, web hosting, VPS, and other related services. In this report,…
-
Reflected XSS Hidden Input in AT&T
•
During my testing of AT&T’s common login page, I discovered a reflected XSS vulnerability in the transactionID parameter.…
-
XSS 101
•
What is XSS? Cross-site scripting (XSS) is the most common vulnerability in web applications and allows an attacker…
-
Stored DOM-based XSS on Xiaomi
•
Yesterday, I discovered a Stored Cross-Site Scripting (XSS) vulnerability on the Xiaomi Forum via Markdown. Today, I’ve found…
-
WinRAR XSS
•
A few days ago, I discovered a Cross-site Scripting (XSS) vulnerability in WinRAR. In this article, I’ll walk…
-
Reflected DOM-based XSS on DomaiNesia
•
In this article, I’ll walk you through how I discovered a Reflected DOM-based Cross-site Scripting (XSS) vulnerability on…
Recent Posts
- Critical SQL Injection in a Major Indonesian Web Hosting PlatformWhile exploring vulnerabilities in a major web hosting company in… Read more: Critical SQL Injection in a Major Indonesian Web Hosting Platform
- Breaking Vercel’s Clone URL with a Simple XSS ExploitDuring my exploration of Vercel’s platform, I discovered a reflected… Read more: Breaking Vercel’s Clone URL with a Simple XSS Exploit
- Bypassing Razer’s WAF for XSSWhile testing Razer’s web application, I identified an XSS vulnerability… Read more: Bypassing Razer’s WAF for XSS
- Finding WordPress Vulnerabilitieson CarGurus with WPScanWhile exploring CarGurus’ bug bounty program, I discovered a reflected… Read more: Finding WordPress Vulnerabilitieson CarGurus with WPScan
- N45HTCTF2023N45HTCTF2023 | “Cyber Security and Indonesian History” N45HT held a… Read more: N45HTCTF2023
Social Media
Advertisement
Tags
API Bug Bounty Capture The Flag Cross-site Scripting CTF ExifTool HTML JavaScript Open Redirection PHP SQL Injection VDP WAF Web Application Firewall XSS XSSR XSSRush