This assumes the url that process the ?next request pass the info in a Crossdomain way... Ie get vars or post.
Everyone does cookies or backend storage.
unless you can compromise the target dns, this is impossible to exploit except for very lousy sites... But if they are bad to this point, you probably already have a local shell access