Top 10 winner
Expression Language Injection
Spring MVC JSP tags evaluate attacker input a second time, so user data reaching attributes such as scope or code is run as Expression Language. The paper reads server scopes and beans, bypasses HttpOnly by echoing JSESSIONID, and adds blind inference using EL ternary operators plus cross-domain script status codes to steal a session character by character.
Record
- Researcher
- Stefano Di Paola and Arshan Dabirsiaghi
- Published by
- repository.root-me.org
- Format
- Whitepaper
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Stefano Di Paola and Arshan Dabirsiaghi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .