Bypassing WAFs with the phantom $Version cookie
portswigger.net | research | #web-security | #cookies | #waf-bypass | #django | #parser-discrepancies | #spring
Summary
Legacy $Version cookies downgrade parsers into RFC2109 mode, and frameworks — Flask, Django, PHP, Spring — disagree on the result. The discrepancies can be abused to smuggle attacks past WAFs.
- Published
- Collected
Skip to content