Exploiting server-side parameter pollution in a REST URL - Lab#05

Опубликовано: 28 Апрель 2026
на канале: Mohd Badrudduja
517
17

In this video, I walkthrough exploiting a server-side parameter pollution (SSPP) vulnerability in a REST-style URL to bypass access controls. By crafting a malicious URL with duplicate path parameters, I successfully gain administrator access and proceed to delete the user carlos.

This lab demonstrates how improper handling of repeated parameters in REST endpoints can lead to privilege escalation and unauthorized actions on the server side.

🔹 Lab Type: Server-Side Parameter Pollution in REST URLs
🔹 Vulnerability: Insecure handling of duplicate REST path parameters
🔹 Attack Goal: Log in as admin and delete carlos

📌 Subscribe for more advanced web security walkthroughs and ethical hacking content! 💻🔓

#SSPP #ServerSideParameterPollution #RESTAPI #WebSecurity #PortSwigger #BugBounty #EthicalHacking #CyberSecurity