πŸ“–
Notes
⌘Ctrlk
πŸ“–
Notes
  • πŸ™ŒWelcome!
    • Penetration Testing
      • ELearnSecurity
      • PortSwigger
        • Cross-origin resource sharing (CORS)
          • Access-Control-Allow-Origin response header
          • Vulnerabilities arising from Misconfigurations
            • Server-generated ACAO header from client-specified Origin header
            • Errors parsing Origin headers
            • Whitelisted null origin value
            • Exploiting XSS via CORS trust relationships
            • Breaking TLS with poorly configured CORS
            • Intranets and CORS without credentials
            • Mitigations
        • Sql Injection
      • TryHackMe
      • Miscellaneous
    • Blue Teaming
    • Infrastructure as a Code (IaC)
    • Orchestration
    • Blockchain
    • Backend
    • Database
    • Testing
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. CyberSecurity
  2. Penetration Testing
  3. PortSwigger
  4. Cross-origin resource sharing (CORS)

Vulnerabilities arising from Misconfigurations

Server-generated ACAO header from client-specified Origin headerErrors parsing Origin headersWhitelisted null origin valueExploiting XSS via CORS trust relationshipsBreaking TLS with poorly configured CORSIntranets and CORS without credentialsMitigations
PreviousAccess-Control-Allow-Origin response header
NextServer-generated ACAO header from client-specified Origin header

Last updated 3 years ago