Vulnerabilities > CVE-2018-11652 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Cirt.Net Nikto 2.1.6
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Nikto 2.1.6 - CSV Injection. CVE-2018-11652. Local exploit for Linux platform |
file | exploits/linux/local/44899.txt |
id | EDB-ID:44899 |
last seen | 2018-06-18 |
modified | 2018-06-18 |
platform | linux |
port | |
published | 2018-06-18 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/44899/ |
title | Nikto 2.1.6 - CSV Injection |
type | local |
Nessus
NASL family Fedora Local Security Checks NASL id FEDORA_2018-5F30937BED.NASL description Security fix for CVE-2018-11652 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-05 modified 2019-01-03 plugin id 120459 published 2019-01-03 reporter This script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/120459 title Fedora 28 : 1:nikto (2018-5f30937bed) NASL family Fedora Local Security Checks NASL id FEDORA_2018-15BF411A32.NASL description Security fix for CVE-2018-11652 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-05 modified 2018-06-20 plugin id 110613 published 2018-06-20 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/110613 title Fedora 27 : 1:nikto (2018-15bf411a32)
Packetstorm
data source | https://packetstormsecurity.com/files/download/148227/nikto216-inject.txt |
id | PACKETSTORM:148227 |
last seen | 2018-06-19 |
published | 2018-06-18 |
reporter | Adam Greenhill |
source | https://packetstormsecurity.com/files/148227/Nikto-2.1.6-CSV-Injection.html |
title | Nikto 2.1.6 CSV Injection |