In this vulnerability, attacker tries to pass parameter in the URL of web application such as “http://........./UserLoginPage.aspx?username=xyz&passwor d = xyz123” Which don’t allow attacker to login and redirect the attacker to custom error page. (Fig4)