Skip to content

Opening book details…

About this document

Exploiting HTTP Request Splitting by Aliyu muhammad gombe is a document available to read on EtoBox.

An HTTP request splitting vulnerability was found in the mail.yandex.ru service. By manipulating the signature parameter in a POST request, an attacker could inject additional HTTP headers and requests, potentially leaking cookies or other sensitive information. Specifically, the vulnerability allowed controlling the Request-URI and injecting custom HTTP headers via CRLF injection in the signature field when submitting forms using multipart/form-data encoding. This could lead to issues like session hijackin

Author
Aliyu muhammad gombe
Language
EN