> For the complete documentation index, see [llms.txt](https://pwc-3.gitbook.io/pwc/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pwc-3.gitbook.io/pwc/ji-shu/webpentest2/untitled-9.md).

# Email Header Injection

​<https://resources.infosecinstitute.com/email-injection/>​

## Inject Cc and Bcc after sender argument <a href="#inject-cc-and-bcc-after-sender-argument" id="inject-cc-and-bcc-after-sender-argument"></a>

The message will be sent to the recipient and recipient1 accounts.

## Inject argument <a href="#inject-argument" id="inject-argument"></a>

The message will be sent to the original recipient and the attacker account.

## Inject Subject argument <a href="#inject-subject-argument" id="inject-subject-argument"></a>

The fake subject will be added to the original subject and in some cases will replace it. It depends on the mail service behavior.

## Change the body of the message <a href="#change-the-body-of-the-message" id="change-the-body-of-the-message"></a>

Inject a two-line feed, then write your message to change the body of the message.
