-
## Service name
Kinsta
## Website
https://kinsta.com/
## Credential
![screenshot 45 _li](https://user-images.githubusercontent.com/40210313/46437332-fa258580-c70f-11e8-9985-17482634cc24.jpg)
…
-
"Upon visiting the domain, I received the message "Sorry, this store is currently unavailable." However, Shopify indicates that the same domain, flagged as vulnerable to takeover by Nuclei, is current…
-
Again, PyPi has changed publishing requirements to use 2FA:
```
WARNING Error during upload. Retry with the --verbose option for more details.
ERROR HTTPError: 400 Bad Request from https://u…
-
I'm unsure if this is a problem with the module, or the following behaviour is by design and the problem needs to be resolved with user config changes in the IDP/ID broker.
My Setup uses OIDC in [K…
-
## Service name
https://www.wix.com/
## Proof
![Screenshot from 2021-08-20 11-48-00](https://user-images.githubusercontent.com/11043604/130177231-d4f4dcb8-d798-431f-979f-c94bc9032d90.png)
#Fin…
-
Update openAPI to the latest version to resolve configUrl overwrite exploit.
https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers/
-
I found a Vulnerable Subdomain and tried my best to takeover it and I almost did it.
The website https://link.zabbix.com/ is in my hand according to Github
but it's not running on my index.html.
…
-
### Pitch
The feature should allow for preventing the profile and followers from moving to another account. If this feature is turned off there should be an X (maybe 7?) day period before the follows…
-
**Bug Description:**
_During sign up we need to verify the email but we can bypass the verification by just clicking the remember me button and changing the URL path._
**Steps to reproduce:**
`…
-
### Pitch
I'm a relatively new Mastodon admin and my server has attracted ~17k users in just a few days. Naturally, this has led to an increase in reports which need moderation.
In many cases, the…
ralfr updated
6 hours ago