[Bug 1095721] New: CVE-2018-11652: CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackersto inject arbitrary OS commands via the Server field in an HTTP response header,which is directly injected into a CSV report.
http://bugzilla.opensuse.org/show_bug.cgi?id=1095721 Bug ID: 1095721 Summary: CVE-2018-11652: CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackersto inject arbitrary OS commands via the Server field in an HTTP response header,which is directly injected into a CSV report. Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.3 Hardware: Other URL: https://smash.suse.de/issue/206943/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: sor.alexei@meowr.ru Reporter: meissner@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2018-11652 CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11652 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-11652.html https://github.com/sullo/nikto/commit/e759b3300aace5314fe3d30800c8bd83c81c29... -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com