rzcoder
rzcoder
> How so? Not a real world use case. > it looks like the length of the padding is not checked Ok, if just this. Can you please check version...
> I doubt that it's "not a real use case" This particular behaviour is present only in the client-side browser, which is usually does not handle incoming requests that can...
I agree that this is a possible situation. But in any case, the client needs to start interacting with the malicious server himself; this is not a situation where an...