Web Hack List

Top 10 winner

Beyond XSS: Edge Side Include Injection

ESI Injection: getting Edge Side Include tags reflected into an HTTP response makes the caching surrogate in front of the application evaluate them, since it cannot tell attacker tags from upstream ones. That yields server-side request forgery from the proxy, exfiltration of HttpOnly cookies, a client-side XSS filter bypass, CRLF header injection and denial of service.

Record

Researcher
Louis Dion-Marcil
Published by
GoSecure
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Louis Dion-Marcil, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .