When Two Parsers Disagree: Exploiting Query String Differentials for XSS
When you spend enough time hunting for vulnerabilities in real-world applications, you start seeing the same patterns over and over again. One pattern that kept showing up in my audits was this: the backend receives some user input, validates it care...
blog.voorivex.team15 min read