Web Hack List

Top 10 winner

Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution

A form with no action attribute submits to the current URL, so framing it with attacker parameters already in the query string produces a request carrying the value twice. JSP returns the query-string copy from request.parameter, so one clickjacked click updates the victim's email while the genuine CSRF token rides along untouched. ASP.NET is affected too, joining duplicates with a comma.

Record

Researcher
lava

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host.