Web Hack List

Top 10 winner

Practical client-side path-traversal attacks

Practical Client Side Path Traversal Attacks

Client side path traversal: JavaScript builds a resource URL by concatenating a user-controlled query parameter into the path, so encoded traversal sequences point the request at a different endpoint. Chained with an open redirect, whose Location a stylesheet load follows, it loads attacker CSS and exfiltrates data from the DOM.

Record

Document
Practical Client Side Path Traversal Attacks
Researcher
@medi_0ne
Published by
mr-medi.github.io
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @medi_0ne, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .