CVE-2017-14087
HIGHTrend Micro OfficeScan XG 12.0 - Host Header Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-14087. PoCs published by hyp3rlinx.
AI-analyzed exploit summary The exploit describes a Host Header Injection vulnerability in TrendMicro OfficeScan, where the 'db_controller.php' script relies on the spoofable HTTP_HOST header instead of SERVER_NAME. This can lead to arbitrary link rendering in cached environments.
Description
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
Exploits (1)
The exploit describes a Host Header Injection vulnerability in TrendMicro OfficeScan, where the 'db_controller.php' script relies on the spoofable HTTP_HOST header instead of SERVER_NAME. This can lead to arbitrary link rendering in cached environments.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N