CSPT

Client Side Path Traversal

Detection

  • Look for file parameters in URLs:

    Copy

    https://example.com/getFile?path=/user/docs/report.pdf
  • Check if JavaScript fetches files:

    Copy

    fetch("/api/getFile?name=report.pdf")

Exploitation

https://app.example.com/delete-session?session=../profile

The resulting DELETE request would target /api/users/profile instead of /api/users/sessions/${sessionId}.

CSPT2CSRF

Burp Extension

Interesting Books

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Last updated