Skip to content

HTTP Header Injection Detection

http-header-injection is a medium severity check in the web category, written in python. Its source is templates/web/injection/http-header-injection.py in cert-x-gen-templates.

Detects HTTP header injection vulnerabilities through response splitting tests

Field Value
Id http-header-injection
Severity medium
Language python
Category web
Author not recorded
Template version not recorded
Confidence not recorded
CVSS not recorded
Weakness not recorded
Tags not recorded
Target kind not recorded
Oracle not recorded

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info http-header-injection

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.