The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Combining web cache poisoning vulnerabilities

Afonso | Last updated: Mar 20, 2024 12:12PM UTC

Hello I am following the solution steps provided and followed the video solution as well but the lab is not solved. When I put "X-Original-Url: /setlang\es" in the GET / . it doesn't redirect me to the localised=1. it just keeps sending me to the regular homepage without the localised=1 parameter. Also I tried using the "X-Original-Url: /setlang\es" in the GET /setlang/es request and it just keeps redirecting me to /setlang/es instead of /?localised=1. What is the issue here?

Dominyque, PortSwigger Agent | Last updated: Mar 21, 2024 12:25PM UTC