peter bassill · operator
$ cve CVE-2018-11652 JSON

CVE-2018-11652 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 24.4% (pctl 98)

Patch early

A public exploit exists.

Description

CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS24.44% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-1236
On CISA KEVno
Public exploityes
Published2018-06-01
Last modified2026-06-17

Affected (1)

VendorProduct
cirt.netnikto

Public exploits

SourceTitleDate
exploit-dbNikto 2.1.6 - CSV Injection2018-06-18

References

→ the Explorer  ·  watch your stack  ·  NVD