From e14b5f953acd439128364e9ab52427691c218cdb Mon Sep 17 00:00:00 2001 From: mgeeky Date: Mon, 7 Mar 2016 18:01:37 +0100 Subject: [PATCH] Modified the Man-In-The-Browser logic of building query string in form fetching. Previous implementation couldn't handle properly option and submit parameters, therefore a MITB-ed user wasn't sending correct query string which should include those two more fields. For instance, bWAPP application (by IT SEC Games) makes choosing a bug to exploit by submitting form consisting of an option and