Web Cache Poisoning
Introduction
Where to find
How to exploit
GET / HTTP/1.1
Host: www.vuln.com
X-Forwarded-Host: evil.comHTTP/1.1 200 OK
Cache-Control: public, no-cache
…
<img href="https://evil.com/a.png" />References
Last updated