I found a kind of reflected cookie based xss i think but i cant figure out how to exploit it I burped the SESSID value and got an xss alert on the response page but how can i apply this on a remote user ? the problem is that the victims cookie is different then mine so the code will not be executed when he will click the link
Aucun commentaire:
Enregistrer un commentaire