Posted by Andrey Stoykov on Sep 08
# Exploit Title: Host Header Injection – silverstripecmsv6.0.0
# Date: 08/2025
# Exploit Author: Andrey Stoykov
# Version: 6.0.0
# Tested on: Debian 12
# Blog:
https://msecureltd.blogspot.com/2025/08/friday-fun-pentest-series-39-host.html
Host Header Injection #1:
Steps to Reproduce:
– Login and change the Host header to Burp Collab domain
– Upon logging in the Collab would get a hit from the IP of the app
// HTTP Post Request
POST…
– Read More – Full Disclosure



