HTTP Response Smuggling
CAPEC-273 · Detailed · Stable
An adversary manipulates and injects malicious content in the form of secret unauthorized HTTP responses, into a single HTTP response from a vulnerable or compromised back-end HTTP agent (e.g., server). See CanPrecede relationships for possible consequences.
likelihood: Medium
severity: High