set-cookie-header

1 article
sort: new top best
clear filter
0 8/10
vulnerability

Technical writeup demonstrating how arbitrary XSS vulnerabilities in Outlook and Twitter were exploited by chaining cookie injection attacks with browser-specific parsing differences. The researchers discovered endpoints that reflected user input into Set-Cookie headers, then leveraged Safari's comma-delimited cookie parsing to inject malicious ClientId/session cookies that would execute stored XSS payloads on victim browsers.

Outlook Twitter Safari Chrome Firefox RFC 2109 Ruby on Rails Microsoft ActionDispatch::Flash
wesecureapp.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details