.NET Framework Cookieless Feature XSS.

multiple XSS at RedBull

if your application relies on cookieless sessions or might receive requests from mobile browsers that require cookieless sessions, using a tilde (“~”) in a path can result in inadvertently creating a new session and potentially losing session data .

<script src="/(A(ABCD))/Script.js"></script>
<script src="/(A(ABCD))/Script.js"></script>




Offensive Cyber Security Researcher At Resecurity

Ahmed Elmalky

