writeups.xyz writeups.xyz / Gareth Heyes (@Garethheyes)

Title Vulnerabilities Programs Authors
Splitting the email atom: exploiting parsers to bypass access controls
Blind CSS Exfiltration: exfiltrate unknown web pages
Exploiting XSS in hidden inputs and meta tags
Bypassing CSP via DOM clobbering
Ambushed by AngularJS: a hidden CSP bypass in Piwik PRO
Exploiting prototype pollution in Node without the filesystem
Server-side prototype pollution: Black-box detection without the DoS
Stealing passwords from infosec Mastodon - without bypassing CSP
Safari is hot-linking images to semi-random websites
Using Hackability to uncover a Chrome infoleak
Bypassing Firefox's HTML Sanitizer API
Widespread prototype pollution gadgets
Bypassing CSP with dangling iframes
Finding DOM Polyglot XSS in PayPal the Easy Way
Bypassing CSP with policy injection
XSS in hidden input fields
XSS without HTML: Client-Side Template Injection with AngularJS