The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Missing identification of response splitting vulnerability

Maurizio | Last updated: Jun 22, 2015 09:00AM UTC

We found a that Burp Suite it doesn't test response splitting vulnerability. For example: www.example.com/about.php?date=%0D%0ATest%3A%20no If the HTTP response get the additional header "Test: no" should be reported. https://www.owasp.org/index.php/HTTP_Response_Splitting Regards

PortSwigger Agent | Last updated: Jul 20, 2015 03:18PM UTC