$100 bounty — XSS & Input Validation
作者通过Google Dork发现一个私有编码平台漏洞,利用RCE获得赏金,并报告两个XSS漏洞。第一个XSS通过上传恶意PDF触发,第二个通过注入大量字符导致DoS。最终获得赏金并解决问题。 2025-12-27 04:43:18 Author: infosecwriteups.com(查看原文) 阅读量:6 收藏

StvRoot

I discovered a private programme via google dork. It was a coding platform.

I found RCE and got a bounty for it. Soon after that I reported 2 XSS. But first of all I would like to say f*ck taxes.

#1 XSS :

After creating a profile there was a upload resume section.

I upload a pdf file from : https://github.com/luigigubello/PayloadsAllThePDFs/tree/main/pdf-payloads

Press enter or click to view image in full size

and achieved XSS. Reported and got paid for it.

#2 Input validation:

When I joined a challenge hosted on the website. In the team_name section I was restricted to 15 chars but when I used Burp I was able to inject fuck load of chars XD . Resulting in DoS

I demostrated a small impact and they agreed.


文章来源: https://infosecwriteups.com/100-bounty-xss-input-validation-1ccfb35c5e1f?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh