Specially crafted "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view