writeups.xyz writeups.xyz / Kleiton Kurti (@Kleiton0x7e)

Title Vulnerabilities Programs Authors
Exploiting HTTP Request Smuggling (TE.CL)— XSS to website takeover
Content-Security-Policy Bypass to perform XSS using MIME sniffing
Leveraging LFI to RCE in a website with +20000 users
Bypassing WAF to perform XSS
Blind SSRF on coda.io