Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

161
Vistas
exploit the JSONP get parameter

I have a URL that returns a JSON with a GET parameter "cb"

https://jsonp.c00kie.ninja/public/jsonp.php?cb

The Get parameter cb takes a value as the name of the function so its like a JSONP.

This URL is sanitized but the parameter can be exploited by passing "alert" function as a parameter

example.

https://jsonp.c00kie.ninja/public/jsonp.php?cb=alert

this URL will return a JSON wrapped by alert. Is there a way to be able to execute a custom defined function.

What I have noticed that it removes brackets and the eval method which is the sensitization process.

about 4 years ago · Juan Pablo Isaza
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda