Web Hack List

Collected research

Exploiting Logged Out XSS Vulnerabilities

Two ways to reach an XSS that only renders when a user is logged out, without waiting for a logout. IE serves uncached responses to XmlHttpRequest from cache, so the flaw can read billing pages. And Flash's addRequestHeader appends a second Cookie header, which PHP reconciles into a junk PHPSESSID: the app sees a logged-out user while the browser still holds real cookies.

Record

Researcher
kuza55
Published by
kuza55.blogspot.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of kuza55, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .