Vulnerabilities > CVE-2018-9137 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Open-Audit 2.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Open-AudIT before 2.2 has CSV Injection.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Open-AudIT 2.1 - CSV Macro Injection. CVE-2018-9137. Webapps exploit for Windows platform |
file | exploits/windows/webapps/44511.txt |
id | EDB-ID:44511 |
last seen | 2018-05-24 |
modified | 2018-04-24 |
platform | windows |
port | |
published | 2018-04-24 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/44511/ |
title | Open-AudIT 2.1 - CSV Macro Injection |
type | webapps |
Packetstorm
data source | https://packetstormsecurity.com/files/download/147346/openaudit21-inject.txt |
id | PACKETSTORM:147346 |
last seen | 2018-04-25 |
published | 2018-04-25 |
reporter | Sureshbabu Narvaneni |
source | https://packetstormsecurity.com/files/147346/Open-AudIT-2.1-CSV-Macro-Injection.html |
title | Open-AudIT 2.1 CSV Macro Injection |