CVE-2018-11652
01.06.2018, 15:29
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.Enginsight
Vendor | Product | Version |
---|---|---|
cirt.net | nikto | 𝑥 ≤ 2.1.6 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases