The return of HTTP Response Splittingā€¦

Redirects allowing header injection used to be easy to turn into . Browsers improved but loopholes are still found every now and then. So now itā€™s empty Location header on Chrome and Location: ws:// on Firefox.

