HTTP Parameter Pollution (HPP) TL;DR: Same parameter sent multiple times — server-side and client-side parsers disagree on which value wins. Bypass filters, alter behaviour. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://portswigger.net/kb/issues/00500300_http-parameter-pollution