Splitting the email atom: exploiting parsers to bypass access controls |
|
|
|
Blind CSS Exfiltration: exfiltrate unknown web pages |
|
|
|
Exploiting XSS in hidden inputs and meta tags |
|
|
|
Bypassing CSP via DOM clobbering |
|
|
|
Ambushed by AngularJS: a hidden CSP bypass in Piwik PRO |
|
|
|
Exploiting prototype pollution in Node without the filesystem |
|
|
|
Server-side prototype pollution: Black-box detection without the DoS |
|
|
|
Stealing passwords from infosec Mastodon - without bypassing CSP |
|
|
|
Safari is hot-linking images to semi-random websites |
|
|
|
Using Hackability to uncover a Chrome infoleak |
|
|
|
Bypassing Firefox's HTML Sanitizer API |
|
|
|
Widespread prototype pollution gadgets |
|
|
|
Bypassing CSP with dangling iframes |
|
|
|
Finding DOM Polyglot XSS in PayPal the Easy Way |
|
|
|
Bypassing CSP with policy injection |
|
|
|
XSS in hidden input fields |
|
|
|
XSS without HTML: Client-Side Template Injection with AngularJS |
|
|
|