HTTP header injection

If we can inject newline into the header we control , then we will be able to insert some additional HTTP Header and some nasty body text. I don't think so that we can compromised a website/server via this vulnerability. But still it is power for Social Engineering attack, Phishing, Redirecting to malicious site, downloading backdoor, virtual defacement, sometime injecting cookie  etc. It is much like XSS.



Read more »