Web Hack List

Collected research

When security features collide

Shows how Cloudflare's email-obfuscation response rewriting can undermine its WAF and browser XSS filters when a site already has reflected XSS. The article illustrates conflicting parser interpretations and the risks of combining security features.

Record

Researcher
James Kettle
Published by
PortSwigger
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .