Web Hack List

Collected research

CRLF Injection Into PHP's cURL Options

CRLF Injection Into PHP’s cURL Options

PHP's cURL header options never reject carriage returns and line feeds, so user data reflected into a server-side API request header can inject extra headers. Adding a double CRLF plus a forged Content-Length lets an attacker append his own request body, making the internal API act on an attacker-chosen method instead of the legitimate one.

Record

Document
CRLF Injection Into PHP’s cURL Options
Researcher
TomNomNom
Published by
Medium
Date
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of TomNomNom, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .