Collected research
Exploring the World of ESI Injection
Edge Side Include injection, where ESI tags reflected into a page are executed by the edge cache rather than the browser. ESI variables and functions such as HTTP_COOKIE, add_header and url_decode let an attacker read HttpOnly cookies, rewrite a JSON response Content-Type to text/html, bypass the WAF and take over accounts.
Record
- Researcher
- Sudhanshu Rajbhar
- Published by
- Medium
- Date
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sudhanshu Rajbhar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .