
Client-Side Path Traversal: When Apps Forge Requests for You
Introduction For years we told ourselves CSRF was a solved problem. The browsers fixed it. Cookies stopped riding along on cross-site requests by default, and CSRF tokens were everywhere. Then a c...





