zlacker

[parent] [thread] 0 comments
1. manana+(OP)[view] [source] 2026-02-03 22:22:27
Say, an endpoint tries to be helpful and responds with “no such user: foo” instead of “no such user”. Or, as a sibling comment suggests, any create-with-properties or set-property endpoint paired with a get-propety one also means game over.

Relatedly, a common exploitation target for black-hat SEO and even XSS is search pages that echo back the user’s search request.

[go to top]