Collected research
Caching the Un-cacheables - Abusing URL Parser Confusions
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
URL parser confusion between a CDN and its origin: the caching front end normalises dot segments in a path while the backend does not, so a request to /Job/../Award/x is served by the vulnerable /Job/ handler but cached under the cacheable /Award/ prefix. This converts a cookie and header only self-XSS into stored XSS served to every visitor.
Record
- Document
- Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
- Published by
- Harel Security Research
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Harel Security Research, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .