Source Code Disclosure in ASP.NET apps
swarm.ptsecurity.com | research | #waf-bypass | #aspnet | #iis | #source-code-disclosure | #cookieless-session
Summary
Building on Cookieless DuoDrop (CVE-2023-36899/36560), the author shows how cookieless sessions in IIS/ASP.NET enable WAF bypass and source code disclosure affecting many .NET web applications.
- Published
- Collected
Skip to content