Cache key injection: Smuggling poison through the door
yeswehack.com | blog | #cloudflare | #stored-xss | #nginx | #cpdos | #web-cache-poisoning | #cache-key-injection | #cache-deception
Summary
How ambiguous NGINX cache keys can enable access-control bypasses, cache deception, CPDoS, stored XSS and origin cache poisoning.
- Published
- Collected
Skip to content