@samm0uda@albinowax Totally agree, chain it with relative path overwrite attacks is an alternative as I mention in the research. But websites without Doctype declaration or nosniff header are quite rare nowadays, that's why I used the open redirect to load the file from my server.