Loading...
Loading...
PHP Web source code CRLF/response splitting audit tool. Identifies user input that enters HTTP response headers, analyzes filtering and encoding of newlines/control characters, and outputs severity ratings, PoCs and fix suggestions (omission is prohibited).
npx skill4agent add 0xshe/php-code-audit-skill php-crlf-auditshared/SEVERITY_RATING.md{C/H/M/L}-CRLF-{serial number}header()setcookie()\r\n%0d%0a\r\n{output_path}/vuln_audit/crlf_{timestamp}.md## 9) Sink Evidence Type ChecklistEVID_CRLF_OUTPUT_POINTEVID_CRLF_USER_INPUT_INTO_HEADER_COOKIEEVID_CRLF_CONTROL_CHAR_FILTERING_ENCODING\r\n⚠️Pending Verification✅Confirmed Exploitable