ZeroHour

CVE-2018-11652

PoC
CVSS 3.0
9.8 critical
EPSS
24%p98
Published
()
Modified
Description

CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

Vendors
cirt.net
Products
nikto
Weakness
CWE-1236
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.