Все публикации

Portswigger: exploiting path delimiters for web cache deception

Portswigger: Exploiting path mapping for web cache deception

Portswigger: Referer-based access control

Portswigger: Multi-step process with no access control on one step

Portswigger: Insecure direct object references

Portswigger: User ID controlled by request parameter with password disclosure

Portswigger: User ID controlled by request parameter with data leakage in redirect

Portswigger: User ID controlled by request parameter, with unpredictable user IDs

Portswigger: User ID controlled by request parameter

Portswigger: Exploiting insecure output handling in LLMs

Portswigger: Indirect prompt injection

Portswigger: Exploiting vulnerabilities in LLM APIs

Portswigger: Exploiting LLM APIs with excessive agency

Portswigger: Method-based access control can be circumvented

Portswigger: URL-based access control can be circumvented

Portswigger: User role can be modified in user profile

Portswigger: User role controlled by request parameter

Portswigger: Unprotected admin functionality with unpredictable URL

Portswigger: Unprotected admin functionality

Portswigger: Exploiting server-side parameter pollution in a REST URL

Portswigger: Exploiting server side parameter pollution in a query string

Portswigger: Exploiting a mass assignment vulnerability

Portswigger: Finding and exploiting an unused API endpoint

Portswigger: Exploiting an API endpoint using documentation