Skip to content
← LibraryTechnique entry
W-REQUEST-SMUGGLE-CLTEImpact

HTTP Request Smuggling — CL.TE

Frontend honours Content-Length, backend honours Transfer-Encoding — smuggle a second request to bypass auth / poison.

§ Where this technique fits

W-REQUEST-SMUGGLE-CLTE is catalogued under the Impact tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    X-Original-URL / X-Rewrite-URL Bypass
    W-HEADER-AUTH-BYPASS · Privilege Escalation
    seen 1×