Hello everyone,
I'm currently learning web app pentesting and testing a VDP program. I have access to the debug.log file and wp-json contents, allowing for username and email enumeration. The WordPress version they're using is 4.9.7.
While I've found various vulnerabilities using WPScan, I'm struggling to find PoCs for many of them. Is there a way to obtain PoCs for WordPress CVEs, or could someone with experience guide me?looking for the unauthenticated ones
I'm open to providing additional information if I've missed anything.
Thank you.
Any body help me I am find information through phone no. Any help me and guide because attacker transfer a money
Читать полностью…this will help:
https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters/blob/master/assets/basics.md
It's just xss, there's no html injection or open redirect, it's just xss, and all it shows is its exploitation, and this as a separate vulnerability should not be considered as a separate vulnerability
Читать полностью…Hahaa I am trying 😅 I thought I can get the credentials for their database but it's so hard I am not able to get any credit
Читать полностью…Good morning Proxy and ip about a site using python 3.8 werkzeug I'm working on a page that gives information like whois. I couldn't figure out how to run code to get a shell on werkzeug pages. Does anyone know or have any ideas?
Читать полностью…I cleared oscp 2021... Prepared from 2019 ... But couldn't get a job. Landed in network engineer...
Читать полностью…Try this app but it for beginners still you can find good bugs using this guide.
https://play.google.com/store/apps/details?id=com.defensiveinet.bugbountyacademy
Hello guys I represent a project and it will have a bug bounty campaign. with who I can speak to advertise it here?
Читать полностью…Yes I am analyzing them . I found the username and password also but I don't know where to use them 😅
Читать полностью…