HTTP Header Command Injection Vulnerability Fuzz & Scanner
You can fuzz HTTP headers for command injection using this tool.
Short Info
Level
Critical
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
5 minutes
Time Interval
3 days
Scan only one
Domain, IPv4
Toolbox
-
HTTP Header Injection vulnerabilities occur when user input is insecurely included within server responses headers.
This tool fuzz the following HTTP headers.
- Accept
- Accept-Charset
- Accept-Datetime
- Accept-Encoding
- Accept-Language
- Authorization
- Cache-Control
- Connection
- Content-Length
- Content-MD5
- Content-Type
- Cookie
- Date
- Expect
- Forwarded
- From
- Host
- If-Match
- If-Modified-Since
- If-None-Match
- If-Range
- If-Unmodified-Since
- Max-Forwards
- Origin
- Pragma
- Proxy-Authorization
- Range
- Referer
- TE
- Upgrade
- User-Agent
- Via
- Warning