vulns.co
/
GKData.io MCP

Back to Payloads

Host Header Injection

Poison password-reset links and cache keys by overriding the Host the app trusts. Prime targets: reset emails, absolute URL generation, and unkeyed cache inputs.

Tags: host-header, password-reset, cache

Controlled probes

  • Host: evil.com
  • X-Forwarded-Host: evil.com
  • X-Forwarded-Server: evil.com
  • X-Host: evil.com
  • Host: target.com\r\nX-Forwarded-Host: evil.com

Source: https://portswigger.net/web-security/host-header