πNew WriteupβοΈ
βββββββββββββββ
πDate: Sat, 29 Apr 2023 14:00:39 GMT
βββββββββββββββ
βοΈTitle: HTTP parameter pollution : Bug bounties [Server-Side ; Client-Side]
βββββββββββββββ
πLink: https://medium.com/p/a03d8d665b15
βββββββββββββββ
Tags: #bug_bounty #hpp #ethical_hacking #website_hacking #http_parameter_pollution
βββββββββββββββ
πDate: Sat, 29 Apr 2023 14:00:39 GMT
βββββββββββββββ
βοΈTitle: HTTP parameter pollution : Bug bounties [Server-Side ; Client-Side]
βββββββββββββββ
πLink: https://medium.com/p/a03d8d665b15
βββββββββββββββ
Tags: #bug_bounty #hpp #ethical_hacking #website_hacking #http_parameter_pollution
Medium
HTTP parameter pollution : Bug bounties [Server-Side ; Client-Side]
Join our Discord server for private learning material and like-minded individuals!
β€· Title: How to Prevent HTTP Parameter Pollution in Laravel: Best Practices & Code Examples
ββββββββββββββββββββββββ
πͺ Author: Pentest_Testing_Corp
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 11 Feb 2025 06:00:34 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #laravel #http_parameter_pollution #penetration_testing #vulnerability
ββββββββββββββββββββββββ
πͺ Author: Pentest_Testing_Corp
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 11 Feb 2025 06:00:34 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #laravel #http_parameter_pollution #penetration_testing #vulnerability
Medium
How to Prevent HTTP Parameter Pollution in Laravel: Best Practices & Code Examples
Introduction
β€· Title: ServerβSide Parameter Pollution: Hijacking Query Strings for AdminβLevel Access
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 17 Jun 2025 05:01:13 GMT
ββββββββββββββββββββββββ
β Tags: #server_side_pollution #http_parameter_pollution #internal_api_exploitation #bug_bounty_tips #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 17 Jun 2025 05:01:13 GMT
ββββββββββββββββββββββββ
β Tags: #server_side_pollution #http_parameter_pollution #internal_api_exploitation #bug_bounty_tips #bug_bounty
Medium
ServerβSide Parameter Pollution: Hijacking Query Strings for AdminβLevel Access
[Write-up] Exploiting Server-Side Parameter Pollution in a Query String.
β€· Title: Prevent HTTP Parameter Pollution in Symfony Apps
ββββββββββββββββββββββββ
πͺ Author: Pentest_Testing_Corp
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 10 Jul 2025 08:50:20 GMT
ββββββββββββββββββββββββ
β Tags: #vulnerability #symfony #cybersecurity #penetration_testing #http_parameter_pollution
ββββββββββββββββββββββββ
πͺ Author: Pentest_Testing_Corp
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 10 Jul 2025 08:50:20 GMT
ββββββββββββββββββββββββ
β Tags: #vulnerability #symfony #cybersecurity #penetration_testing #http_parameter_pollution
Medium
Prevent HTTP Parameter Pollution in Symfony Apps
HTTP Parameter Pollution (HPP) is a lesser-known but impactful web vulnerability that attackers use to manipulate query or form parametersβ¦
β€· Title: Critical Flaw (CVE-2025-7783, CVSS 9.4) in Form-Data Library Exposes Millions of Apps to Multipart Injection & RCE
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 23 Jul 2025 03:01:20 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CVE_2025_7783 #cybersecurity #Form_Data #HTTP Parameter Pollution #javascript #Multipart Injection #rce #Vulnerability
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 23 Jul 2025 03:01:20 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CVE_2025_7783 #cybersecurity #Form_Data #HTTP Parameter Pollution #javascript #Multipart Injection #rce #Vulnerability
Daily CyberSecurity
Critical Flaw (CVE-2025-7783, CVSS 9.4) in Form-Data Library Exposes Millions of Apps to Multipart Injection & RCE
A critical vulnerability (CVE-2025-7783, CVSS 9.4) in the Form-Data JavaScript library allows multipart injection and potential RCE due to predictable boundary values.
β€· Title: Critical Axios Flaw (CVE-2025-54371) in Form-Data Dependency Exposes Millions to HTTP Manipulation
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 25 Jul 2025 00:28:21 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #Axios #CVE_2025_54371 #cybersecurity #Form_Data #HTTP Parameter Pollution #javascript #Multipart Form_Data #Vulnerability
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 25 Jul 2025 00:28:21 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #Axios #CVE_2025_54371 #cybersecurity #Form_Data #HTTP Parameter Pollution #javascript #Multipart Form_Data #Vulnerability
Daily CyberSecurity
Critical Axios Flaw (CVE-2025-54371) in Form-Data Dependency Exposes Millions to HTTP Manipulation
A critical flaw (CVE-2025-54371, CVSS 7.5) in the form-data package, used by Axios 1.10.0, allows attackers to predict multipart boundaries, risking HTTP parameter pollution and injection. Update to 1.11.0 now!
β€· Title: The WAF Deception: 70% of Firewalls Bypassed by HTTP Parameter Pollution and JS Injection
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 06 Aug 2025 02:36:36 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #bypass #cybersecurity #ETHIACK #HTTP Parameter Pollution #JavaScript Injection #vulnerability #WAF #Web Application Firewall
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 06 Aug 2025 02:36:36 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #bypass #cybersecurity #ETHIACK #HTTP Parameter Pollution #JavaScript Injection #vulnerability #WAF #Web Application Firewall
Penetration Testing Tools
The WAF Deception: 70% of Firewalls Bypassed by HTTP Parameter Pollution and JS Injection
A new report reveals that over 70% of WAFs can be bypassed by combining JavaScript injection with HTTP parameter pollution, fooling security systems with malformed requests.
β€· Title: Cache Key Injection: Chaining Cache-Poisoning and CRLF Using an Unkeyed Parameter
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 07 Oct 2025 08:34:36 GMT
ββββββββββββββββββββββββ
β Tags: #crlf_injection #web_cache_poisoning #cache_key_injection #http_parameter_pollution #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 07 Oct 2025 08:34:36 GMT
ββββββββββββββββββββββββ
β Tags: #crlf_injection #web_cache_poisoning #cache_key_injection #http_parameter_pollution #bug_bounty
Medium
Cache Key Injection: Chaining Cache-Poisoning and CRLF Using an Unkeyed Parameter
Learn how cache key injection works, why it leads to large-scale cache poisoning, and the real-world risks for modern web applications.
β€· Title: Cache Key Injection: Chaining Cache-Poisoning and CRLF Using an Unkeyed Parameter
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 05 Jan 2026 13:14:32 GMT
ββββββββββββββββββββββββ
β Tags: #crlf_injection #web_cache_poisoning #cache_key_injection #http_parameter_pollution #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 05 Jan 2026 13:14:32 GMT
ββββββββββββββββββββββββ
β Tags: #crlf_injection #web_cache_poisoning #cache_key_injection #http_parameter_pollution #bug_bounty
Medium
Cache Key Injection: Chaining Cache-Poisoning and CRLF Using an Unkeyed Parameter
Learn how cache key injection works, why it leads to large-scale cache poisoning, and the real-world risks for modern web applications.
β€· Title: How a Simple HPP Bug Earned $700 on Twitter
ββββββββββββββββββββββββ
πͺ Author: ab.infosec
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 06 Jan 2026 20:27:18 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #bug_bounty #websecurity_testing #http_parameter_pollution
ββββββββββββββββββββββββ
πͺ Author: ab.infosec
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 06 Jan 2026 20:27:18 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #bug_bounty #websecurity_testing #http_parameter_pollution
Medium
How a Simple HPP Bug Earned $700 on Twitterπ¨
Sometimes, finding a real bug doesnβt require advanced exploits or zero-days.
β€· Title: Exploiting Server-Side Parameter Pollution in a REST URL
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 03 Mar 2026 07:01:54 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #http_parameter_pollution #broken_access_control #account_takeover #bug_bounty_tips
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 03 Mar 2026 07:01:54 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #http_parameter_pollution #broken_access_control #account_takeover #bug_bounty_tips
Medium
Exploiting Server-Side Parameter Pollution in a REST URL
How the REST Parameter Manipulation Led to Administrator Account Takeover.
β€· Title: HTTP Parameter Pollution (HPP)
ββββββββββββββββββββββββ
πͺ Author: Lost_hacker
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 11 Mar 2026 04:56:51 GMT
ββββββββββββββββββββββββ
β Tags: #http_parameter_pollution #bugbounty_writeup #bug_bounty #parameter_pollution #hacking
ββββββββββββββββββββββββ
πͺ Author: Lost_hacker
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 11 Mar 2026 04:56:51 GMT
ββββββββββββββββββββββββ
β Tags: #http_parameter_pollution #bugbounty_writeup #bug_bounty #parameter_pollution #hacking
Medium
HTTP Parameter Pollution (HPP)
1. Topic Overview β What, Why, Where, How, Which