Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-6889. PoCs published by Navina Asrani.
AI-analyzed exploit summary The exploit describes a Host Header Injection vulnerability in TypeSetter CMS 5.1, allowing arbitrary web page redirection and potential attacks like password reset or cache poisoning. The PoC demonstrates tampering the Host header to redirect to an arbitrary domain.
Description
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
Exploits (1)
The exploit describes a Host Header Injection vulnerability in TypeSetter CMS 5.1, allowing arbitrary web page redirection and potential attacks like password reset or cache poisoning. The PoC demonstrates tampering the Host header to redirect to an arbitrary domain.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H