Back to directory
WRITEUP #241

Next.js and cache poisoning: a quest for the black hole

OtherWeb cache poisoning
by@zhero___(Rachid.A)
Bounty
5,000
Program
Vercel (NextJS)
Published
Jun 24, 2024
Added to HackDex
Jul 1, 2024
Read Full Writeuphttps://zhero-web-sec.github.io/research-and-things/nextjs-and-cache-poisoning-a-quest-for-the-black-hole
RELATED WRITEUPS
Gotta cache 'em all: bending the rules of web cache exploitation
OtherWeb cache poisoning
Splitting the email atom: exploiting parsers to bypass access controls
OtherWeb cache poisoning
Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
OtherWeb cache poisoning
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass

Built with ❤️ by Shubham Rawat