redirect?target=https://www
Summary:
Security is asking why it is not blocked to use redirect?target=https://www after the subdomain? It results in vulnarabilities. What can we do about it?
Content (please ensure you mask any confidential information):
Any generic website I try on the web blocks this (results in a 404). However, when adding this behind my clients subdomain (branded) I actually get redirected. Client does not want this.
Why is this happening? And, how can I stop it?
Tagged:
0