Exploitation Summary
EIP tracks 2 public exploits for CVE-2016-10073.
PoCs published by Dawid Golunski, Jay Turla, Medz Barao, including Metasploit module auxiliary/scanner/http/host_header_injection.
AI-analyzed exploit summary This exploit leverages CVE-2016-10073 (Header Injection) and CVE-2016-10033 (RCE) in Vanilla Forums <= 2.3 to achieve unauthenticated remote code execution via crafted Host headers in password reset requests.
Description
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.
Exploits (2)
This exploit leverages CVE-2016-10073 (Header Injection) and CVE-2016-10033 (RCE) in Vanilla Forums <= 2.3 to achieve unauthenticated remote code execution via crafted Host headers in password reset requests.
This Metasploit module scans for HTTP Host header injection vulnerabilities by sending requests with manipulated Host, X-Host, and X-Forwarded-Host headers and checking for their reflection in the response.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N