Tuesday, March 13, 2018

Java: setCharacterEncoding NOT affected by HTTP Response Splitting

String attacker_controlled_charset = "ISO-8859-1%0d%0aHacked-Response-Header: 1337";

