help@cyb4rgeek.xyz

+1 (512) 588 6950

Exploring the World of ESI Injection

Home/Exploring the World of ESI Inj...
Exploring the World of ESI Injection
Exploring the World of ESI Injection bez0x January 03, 2023

The Story Begins

https://globe.redacted.com/?showFooter=um6k%3c!--esi--%3e8omf%3c!--esx--%3eekdi

Note: This issue was generated by the Burp extension: Active Scan++.
Issue detail
The application appears to support Edge Side Includes: The following probe was sent: um6k<!–esi–>8omf<!–esx–>ekdi In the response, the ESI comment has been stripped: um6k8omf<!–esx–>ekdi Refer to https://gosecure.net/2018/04/03/beyond-xss-edge-side-include-injection/ for further information

 

https://docs.oracle.com/cd/A97335_02/caching.102/a90372/esi.htm#633138
https://www.akamai.com/site/zh/documents/technical-publication/akamai-esi-developers-guide-technical-publication.pdf
https://www.akamai.com/site/zh/documents/technical-publication/akamai-esi-developers-guide-technical-publication.pdf

 

Leave a Reply