DOM XSS in document.write sink using source location.search – PortSwigger Write Up
Learn how to exploit DOM XSS in document.write by escaping from an img element and executing JavaScript code through the search bar.
123 articles
Learn how to exploit DOM XSS in document.write by escaping from an img element and executing JavaScript code through the search bar.
Step-by-step resolution of the PortSwigger lab on Stored XSS in HTML context without encoding, exploiting comments to execute malicious JavaScript code.
Step-by-step resolution of the PortSwigger lab on Reflected XSS in HTML context without encoding, exploiting the search bar to execute JavaScript code.
Learn to exploit race condition vulnerabilities in file uploads to execute malicious PHP code before the server applies security validations.
Step-by-step resolution of the PortSwigger lab on remote code execution through uploading a polyglot web shell, exploiting file content validation.
Learn to bypass file upload restrictions using the extension obfuscation technique with null bytes to execute PHP code.
Learn to bypass file extension blacklists using alternative PHP extensions and Apache configurations to execute malicious code.
Learn to exploit file upload vulnerabilities using path traversal techniques to bypass execution restrictions and execute malicious PHP code.
Complete guide on SQL Injection: SQL fundamentals, types of injections (Union-based, Error-based, Boolean-based, Time-based), exploitation techniques, and practical examples with code.
If you like the content and want to support the project, you can buy me a coffee. Your support helps keep the site active and create more quality content.
Buy me a coffeeThanks for your support 🙏