$100 bounty — XSS & Input Validation
作者通过Google Dork发现一个私密编程平台并利用RCE漏洞获得赏金。随后报告两个XSS漏洞:一是上传简历时的XSS;二是输入验证问题导致DoS。 2025-12-27 04:43:18 Author: infosecwriteups.com(查看原文) 阅读量:2 收藏

StvRoot

I discovered a private programme via google dork. It was a coding platform.

I found RCE and got a bounty for it. Soon after that I reported 2 XSS. But first of all I would like to say f*ck taxes.

#1 XSS :

After creating a profile there was a upload resume section.

I upload a pdf file from : https://github.com/luigigubello/PayloadsAllThePDFs/tree/main/pdf-payloads

Press enter or click to view image in full size

and achieved XSS. Reported and got paid for it.

#2 Input validation:

When I joined a challenge hosted on the website. In the team_name section I was restricted to 15 chars but when I used Burp I was able to inject fuck load of chars XD . Resulting in DoS

I demostrated a small impact and they agreed.


文章来源: https://infosecwriteups.com/100-bounty-xss-input-validation-1ccfb35c5e1f?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh