Understanding Web Cache Poisoning via Unkeyed Headers: A PortSwigger Lab Walkthrough (opens in new tab)
Imagine being able to send a single HTTP request and have every visitor to a website execute attacker-controlled JavaScript.
Read the original article