Bug ID 1095721
Summary CVE-2018-11652: CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackersto inject arbitrary OS commands via the Server field in an HTTP response header,which is directly injected into a CSV report.
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/206943/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee sor.alexei@meowr.ru
Reporter meissner@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2018-11652

CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers
to inject arbitrary OS commands via the Server field in an HTTP response
header,
which is directly injected into a CSV report.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11652
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-11652.html
https://github.com/sullo/nikto/commit/e759b3300aace5314fe3d30800c8bd83c81c29f7


You are receiving this mail because: