Vulnerability field guide
Host Header Injection
Applications that trust the Host header to build absolute URLs can be tricked into emailing attacker-controlled reset links and poisoning caches. Here is how it works and how to validate your way out.
2 articles 8 min total Overview to advanced techniques
Host Header Injection techniques
1 focused deep-dive