Host header injection hunter
Finds and verifies Host header injection vulnerabilities in authorized web targets, covering password reset poisoning, cache poisoning, routing and path-override SSRF, and OAuth/OIDC poisoning. Use when testing a target's forgot-password flow, CDN or reverse-p