Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2950Supply Chain Pollution: Hunting a 16 Million Download/Week npm Package Vulnerability for a CTF Challenge Prototype pollution Node.js third-party modules Eugene Lim (@spaceraccoonsec) Bug Bounty2020-12-232023-06-13
2185"A tale of making internet pollution free" - Exploiting Client-Side Prototype Pollution in the wild Prototype pollution XSS Apple Atlassian Mozilla HubSpot Segment Analytics Sergey Bobrov (@black2fan) Bug Bounty2021-09-282023-06-13
2098Insufficient Redirect URI validation: The risk of allowing to dynamically add arbitrary query parameters and fragments to the redirect_uri OAuth Prototype pollution GitHub Microsoft StackExchange Lauritz Holtmann (@_lauritz_) Bug Bounty2021-11-062023-06-13
1621Prototype Pollution in fast-xml-parser Prototype pollution NA Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2022-04-142023-06-13
1443Widespread prototype pollution gadgets Prototype pollution NA Gareth Heyes (@garethheyes) Bug Bounty2022-06-212023-06-13
1380Remote Code Execution via Prototype Pollution in Blitz.js Prototype pollution RCE Blitz.js Paul Gerste Bug Bounty2022-07-122023-06-13
1251Mining Node.js Vulnerabilities via Object Dependence Graph and Query RCE OS command injection Prototype pollution Path traversal NA Song Li Bug Bounty2022-08-102023-06-13
1186But You Told Me You Were Safe: Attacking The Mozilla Firefox Renderer (Part 1) Browser hacking RCE Prototype pollution Mozilla Hossein Lotfi (@hosselot) Bug Bounty2022-08-232023-06-13
1054TypeORM Prototype Pollution Leading To SQL Injection (CVE-2022-36531) DoS SQL injection TypeORM Norbert Szetei (@73696e65) Bug Bounty2022-09-212023-06-13
838Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js RCE Prototype pollution DoS Rocket.Chat NPM CLI Parse Server Node.js Mikhail Shcherbakov Bug Bounty2022-11-112023-06-13
618Prototype Pollution in Python Prototype pollution DoS NA Abdulraheem Khaled (@Abdulrah33mK) Bug Bounty2023-01-042023-06-13
443Detecting Server-Side Prototype Pollution Server-side prototype pollution NA Daniel Thatcher (@_danielthatcher) Bug Bounty2023-02-152023-06-13
442Server side prototype pollution, how to detect and exploit Server-side prototype pollution RCE NA BitK (@BitK_) Bug Bounty2023-02-152023-06-13
441Server-side prototype pollution: Black-box detection without the DoS Server-side prototype pollution RCE NA Gareth Heyes (@garethheyes) Bug Bounty2023-02-152023-06-13
414Vulnerability write-up - "Dangerous assumptions" Prototype pollution SQL injection Security code review DIVD Thomas Rinsma (@thomasrinsma) Bug Bounty2023-02-222023-06-13
327EJS - Server Side Prototype Pollution gadgets to RCE Server-side prototype pollution RCE Security code review Node.js third-party modules (EJS) Mizu (@kevin_mizu) Bug Bounty2023-03-092023-06-13
269Exploiting prototype pollution in Node without the filesystem Server-side prototype pollution RCE NA Gareth Heyes (@garethheyes) Bug Bounty2023-03-232023-06-13
240Finding RCE in NodeJS templating engine %27Eta%27 - CVE-2022-25967 RCE Server-side prototype pollution Security code review Eta Rayhan Ahmed Niloy (@Rayhan0x01) Bug Bounty2023-04-012023-06-13
214A successful prototype pollution chained to a DOM XSS Prototype pollution DOM XSS NA Allam Rachid (@blank_cold) Bug Bounty2023-04-102023-06-13
33Prototype Pollution Akamai Client-side prototype pollution WAF bypass NA Sudhanshu Rajbhar (@sudhanshur705) Bug Bounty2023-06-032023-06-13