← back
CVE-2018-11652

CVE-2018-11652

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 25%
from disclosure to weapon17 days
Published on NVDJun 1
1st PoC+17d
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.