nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-6889 CVE-2018-6889
HIGH
TypeSetter CMS 5.1 - 'Host' Header Injection
Record summary
CVE-2018-6889 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTypeSetter CMS 5.1 - 'Host' Header InjectionExploitDB exploitby Navina AsraniNot analyzed1 file
References
3securitywarrior9.blogspot.in
https://securitywarrior9.blogspot.in/2018/02/host-header-injection-type-setter-cms-51.html 44028exploit
https://www.exploit-db.com/exploits/44028