Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Source Code Disclosure in ASP.NET apps

Summary

Building on Cookieless DuoDrop (CVE-2023-36899/36560), the author shows how cookieless sessions in IIS/ASP.NET enable WAF bypass and source code disclosure affecting many .NET web applications.
Published
Collected

original ↗

Related coverage

back