Vulnerabilities
$_POST['poll_id'] is not escaped properly.
2 MIN READ
Vulnerabilities
$_POST['poll_id'] is not escaped properly.
2 MIN READ
Vulnerabilities
By default it's possible to upload .html files. So we can put XSS there.
1 MIN READ
Vulnerabilities
Nonce token is not checked inside install_new_favicon() function.
1 MIN READ
Vulnerabilities
$_GET['cs-msg'] is not escaped.
1 MIN READ
Ctf
Example of hash length extension vulnerability
4 MIN READ
Vulnerabilities
googleapis.com domain is whitelisted by default.
1 MIN READ
Vulnerabilities
$_GET['vid'] is not escaped.
2 MIN READ
Vulnerabilities
Every registered user can change livefyre_site_id and livefyre_site_key.
1 MIN READ
From 0 to pentesting hero
Retrieving parameters from the user and later displaying them on the website always carries risk of XSS attack. But can you perform such attack without using the HTML tag?
21-03-2019
3 MIN READ