V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-11652
DEB
CriticalConfirmedExploit available

CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an H…

CVSS
9.8
Critical
EPSS
0.34
p97
Published
2018-01-01
Updated
2018-01-01
Description

CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

Tags · CWE
Pre-auth
CWE-1236
Affected products
NiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNiktoNikto
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.336 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
44899
exploitdb · https://www.exploit-db.com/exploits/44899
Enterprise
Affected software
ProductVendorStatus
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
niktoTracked
Source databases
DEB
CVE
UBU
Related vulnerabilities