th3hidd3mist
  • About
  • RSS
  • About
  • RSS

A few vulnerabilities in DotCMS

2023-06-27
Here I explain a few bugs I found and go into my methodology.

Great, another OSWE blog

2022-06-20
My thoughts on the OSWE exam

Effortlessly finding Cross Site Script Inclusion (XSSI) & JSONP

2019-12-27
Methdology for XSSI & JSONP vulnerabilities.

Broken API Authorization

2019-11-12
A good ol’ API authorization bug.
© 2023 Powered by Hugo Theme made by panr