Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Bypassing WAFs with the phantom $Version cookie

Summary

Legacy $Version cookies downgrade parsers into RFC2109 mode, and frameworks — Flask, Django, PHP, Spring — disagree on the result. The discrepancies can be abused to smuggle attacks past WAFs.
Published
Collected

original ↗

Related coverage

back