About this document
Exploiting HTTP Request Splitting by Aliyu muhammad gombe is a document available to read on EtoBox.
An HTTP request splitting vulnerability was found in the mail.yandex.ru service. By manipulating the signature parameter in a POST request, an attacker could inject additional HTTP headers and requests, potentially leaking cookies or other sensitive information. Specifically, the vulnerability allowed controlling the Request-URI and injecting custom HTTP headers via CRLF injection in the signature field when submitting forms using multipart/form-data encoding. This could lead to issues like session hijackin
- Author
- Aliyu muhammad gombe
- Language
- EN