HTTP response splitting
Theory
Practice
GET /index.php?question=answer%0D%0AInjection:%20Pwned%0D%0A HTTP/1.1HTTP/1.1 200 OK
[...]
X-Custom-Question: answer
Injection: Pwned
[...]Reflected XSS
Resources
Last updated
Was this helpful?
