The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Host header poisoning

Adrian | Last updated: Oct 28, 2024 08:43AM UTC

Why did burp scanner discover the Host header poisoning vulnerability on this vulnerable code? ``` <?php $host = $_SERVER['HTTP_HOST']; //echo "The host is: " . $host; header('Location: ' . $host . "/test"); exit(); ``` https://imgur.com/3iXlxNi https://imgur.com/UH8MLVu

Syed, PortSwigger Agent | Last updated: Oct 29, 2024 09:30AM UTC