Kulkan

Description

kulkan-1

Challenge: Linkarrow-up-right

Sponsor: Kulkan Securityarrow-up-right

Solution

Dive into source code: challenge.jsarrow-up-right

1. params are taken from URL or the document element.

2. XSS Vector

3. Prototype Pollution Vector, > Morearrow-up-right <

Payload:

URL Payload:

circle-info
circle-check

Last updated