webPromedium

Lab 33 — PulsePress — Reflected XSS in Search Page

hackadvisor

Task: blog platform with search reflecting input in two places with inconsistent sanitization. Solution: exploit reflected XSS in unencoded reflection point, use same-origin comment posting to exfiltrate admin's flag cookie when external requests are blocked.

$ ls tags/ techniques/
admin_bot_exploitationreflected_xss_exploitationsame_origin_data_exfiltrationcookie_theft_via_javascriptdifferential_encoding_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups