Securing the Computer Security Course: Discovering a Session Hijacking Vulnerability in EPFL's COM-301 Website |
|
|
|
Session Token Enumeration in RWS WorldServer |
|
|
|
[Netflix][Smart TV] — Chaining Self-XSS with Session poisoning. |
|
|
|
Cengage LTI Session Management Leakage |
|
|
|
Pwning a Cisco RV340 with a 4 bug chain exploit |
|
|
|
Flask Security |
|
|
|
Pre-Auth RCE in Moodle Part II - Session Hijack in Moodle's Shibboleth |
|
|
|
Exploiting Redash instances with CVE-2021-41192 |
|
|
|
Account Takeovers — Believe the Unbelievable |
|
|
|
Exploiting outdated Apache Airflow instances |
|
|
|
[Writeup][Bug Bounty][Instagram] Instagram Still Send New DMs and Video Calls to Device After Logout [ID][EN] |
|
|
|
Weak session validation bug let you login even after changing the session IDs and logging out from the accounts |
|
|
|
Breaking the Competition (Bug Bounty Write-up) |
|
|
|
A $25 Easy Bug. |
|
|
|
Reusing Cookies |
|
|
|
CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] |
|
|
|
Baking Flask cookies with your secrets |
|
|
|
Broken Authentication — Bug Bounty |
|
|
|
CVE-2018-13784: PrestaShop 1.6.x Privilege Escalation |
|
|
|
Luminate Store Basics defacement and potential takeover |
|
|
|
OpenProject Session Management Security Vulnerability aka CVE-2017-11667 |
|
|
|