writeups.xyz
/
Kleiton Kurti (@Kleiton0x7e)
Title
Vulnerabilities
Programs
Authors
Exploiting HTTP Request Smuggling (TE.CL)— XSS to website takeover
HTTP Request Smuggling
XSS
Undisclosed
Kleiton Kurti (@Kleiton0x7e)
Content-Security-Policy Bypass to perform XSS using MIME sniffing
XSS
CSP Bypass
Undisclosed
Kleiton Kurti (@Kleiton0x7e)
Leveraging LFI to RCE in a website with +20000 users
LFI
RCE
Undisclosed
Kleiton Kurti (@Kleiton0x7e)
Bypassing WAF to perform XSS
XSS
Undisclosed
Kleiton Kurti (@Kleiton0x7e)
Blind SSRF on coda.io
SSRF
Coda
Kleiton Kurti (@Kleiton0x7e)
Page 1 of 1