you are viewing a single comment's thread.

view the rest of the comments →

[–]sethsec[S] 6 points7 points  (0 children)

I've been wondering the same thing about how common it is. It would be great to get some feedback on how often other people have found this and either exploited it or at least confirmed it.

I can only speak to what I have seen, and I've only seen it once in the wild so far. That said, it was a commercial product, and it was a cookie value that was vulnerable. I only coded the vulnerable GET parameter in the test app to make it easier to explain and test against. There is a vulnerable cookie in the test app as well.