{"content":"<section class=\"cache-poisoning-response\"><h3>Dynamic Asset Loading</h3><p><strong>Banner Key:</strong> Welcome to the shared cache demo</p><p><strong>Active Asset URL:</strong> <a href=\"https://cdn.vulnerableapp.local/assets/cache-poisoning-demo.js\" target=\"_blank\" rel=\"noreferrer\">https://cdn.vulnerableapp.local/assets/cache-poisoning-demo.js</a></p><div class=\"asset-preview-box\">  <div class=\"asset-preview-title\">Security Monitor: Context Loading</div>  <iframe src=\"https://cdn.vulnerableapp.local/assets/cache-poisoning-demo.js\" class=\"asset-preview-iframe\"></iframe>  <p class=\"asset-preview-note\">The browser is attempting to load the resource from the host above. Use the <b>Network Tab</b> to verify the origin.</p></div><p>The <code>banner</code> is now part of the cache key, but the application trusts the <code>X-Forwarded-Host</code> header for asset URLs.</p><p>If the cache ignores this header, the asset location can be poisoned.</p></section>","isValid":true}