Puzzle 02

Bookmarked!

Leverage a PHP trick to bypass CSP

PRO Hard < 1 Hr. 43
Course

This challenge is a puzzle inspired by a tweet from @pilvar222. Your objective is to trigger a Cross-Site Scripting (XSS) vulnerability by exploiting limitations in PHP's <code>header()</code> function related to setting Content-Security Policies (CSP).

Topics
CSP XSS

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.