It was a simple payload as the CRLF payloads looks like was %0d%0aContent-Type:text/html%0a%0a%0a%0a%0a<script>alert(1)</script>

Khaled Mohamed
Khaled Mohamed

Written by Khaled Mohamed

Bug Hunter || Security Researcher at Hackerone, Detectify Crowdsource, Synack Red Team.

Responses (1)