Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14523. PoCs published by Samrat Das.
AI-analyzed exploit summary This is a writeup describing a Host Header Injection vulnerability in Wonder CMS 2.3.1, which allows arbitrary web page redirection and potential attacks like password reset or web cache poisoning. The PoC involves intercepting a web request and modifying the Host header to demonstrate the vulnerability.
Description
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack
Exploits (1)
This is a writeup describing a Host Header Injection vulnerability in Wonder CMS 2.3.1, which allows arbitrary web page redirection and potential attacks like password reset or web cache poisoning. The PoC involves intercepting a web request and modifying the Host header to demonstrate the vulnerability.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N