Host Header Injection: How a Spoofed Header Hijacks Password-Reset Links
Applications that trust the Host header to build absolute URLs can be tricked into emailing attacker-controlled reset links and poisoning caches. Here is how it works and how to validate your way out.