Skip to content
Back to skills

Web Http Parameter Pollution

ASecurity

Send the same parameter more than once so the WAF/validator and the backend disagree on which value wins — bypassing filters, access control, or business logic. Load on "HPP", when a value is validated at one layer but used at another, or when a WAF blocks a payload you need to slip past. Signals: proxies/gateways in front of the app, duplicated params reflected inconsistently.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsrustgophpnodeexpresstestingfrontendbackend

Works with

  • cli

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add NoorQureshi/SploitAgent --skill web-http-parameter-pollution --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Web Http Parameter Pollution?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Web Http Parameter Pollution
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-web-http-parameter-pollution/badge)](https://www.skillsdirectory.com/skills/noorqureshi-web-http-parameter-pollution)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: web-http-parameter-pollution
description: >
  Send the same parameter more than once so the WAF/validator and the backend disagree on which
  value wins — bypassing filters, access control, or business logic. Load on "HPP", when a value is
  validated at one layer but used at another, or when a WAF blocks a payload you need to slip past.
  Signals: proxies/gateways in front of the app, duplicated params reflected inconsistently.
domain: web
type: technique
stability: learning
modes: [pentest, bugbounty]
severity: medium
owasp: [A03]
cwe: [CWE-235]
tools: [burp]
schema_version: 1
---

# HTTP parameter pollution

## When it applies
A request passes through more than one component that parses parameters — a WAF/gateway, then the
app; or a frontend that builds a backend request. If they resolve a duplicated parameter
differently, you can show one value to the guard and another to the logic.

## Why it works
There is no single rule for `?x=a&x=b`: PHP/Apache take the **last**, ASP/IIS **concatenates**
(`a,b`), classic JSP takes the **first**, Node/Express makes an **array**. When the validator and
the consumer sit on different stacks, a value that passes validation isn't the value that's used.

## Method
1. **Map the parsing**: send `?p=1&p=2` (and body dups) and observe which value the response reflects
   or acts on — that tells you first/last/concat/array.
2. **Split a blocked payload**: if a WAF blocks `q=<svg onload=..>`, try `q=<svg&q=onload=..>` where
   the backend concatenates — the signature never appears whole to the WAF.
3. **Override server-side params**: append your own copy of a param the app also sets internally
   (e.g. `role`, `amount`, `redirect_uri`) so your last-wins value overrides the trusted one.
4. **Access control / logic**: pollute IDs or flags where the auth check reads one occurrence and the
   data layer reads another.
5. **Client-side HPP**: when a link/form is built from your input, inject `&`-encoded params to add
   fields to the generated request.

## Gotchas
- Behaviour is stack-specific — always confirm the parsing empirically before relying on it.
- Body vs query vs path params may parse differently in the same app; test each channel.
- Concatenation (`a,b`) can corrupt the payload — order the duplicates to land valid syntax.

## Verify success
The duplicated parameter produces a different outcome than the single one — a filter is bypassed, an
internal value overridden, or a logic/authz decision changes — reproducibly.

## References
OWASP Testing Guide (HPP); PortSwigger notes on parameter parsing; framework parameter-precedence tables.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…