Exploitation Summary
EIP tracks 2 public exploits for CVE-2017-1000209. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary This repository contains the source code of the vulnerable version of the nv-websocket-client library (CVE-2017-1000209), including detailed changelogs and implementation files. It provides technical insights into the library's structure and changes but does not include an exploit PoC.
Description
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.
Exploits (2)
This repository contains the source code of the vulnerable version of the nv-websocket-client library (CVE-2017-1000209), including detailed changelogs and implementation files. It provides technical insights into the library's structure and changes but does not include an exploit PoC.
This repository contains the source code of the vulnerable version of the nv-websocket-client library (CVE-2017-1000209), along with detailed changelog documentation. It does not include an exploit PoC but provides the vulnerable codebase for analysis.
References (1)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N