github.com
https://github.com/yzmcms/yzmcms/issues/28 CVE-2019-16532
MEDIUM
YzmCMS 5.3 - 'Host' Header Injection
Record summary
CVE-2019-16532 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBYzmCMS 5.3 - 'Host' Header InjectionExploitDB exploitby Debashis PalNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-16532 Exploit Databaseexploit
https://www.exploit-db.com/exploits/47422