When Two Parsers Disagree: Exploiting Query String Differentials for XSS
Feb 10 · 15 min read · When you spend enough time hunting for vulnerabilities in real-world applications, you start seeing the same patterns over and over again. One pattern that kept showing up in my audits was this: the backend receives some user input, validates it care...
Join discussion

