CVE-2018-11652
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 25%
from disclosure to weapon17 days
Published on NVDJun 1
1st PoC+17d
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/44899/unverifiedexploitdbwww.exploit-db.com/exploits/44899unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.