6.1

CVE-2017-7725

Exploit
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ConcretecmsConcrete Cms Version8.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.75% 0.843
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://hyp3rlinx.altervista.org/advisories/CONCRETE5-v8.1.0-HOST-HEADER-INJECTION.txt
Third Party Advisory
Exploit
http://www.securityfocus.com/bid/97649
Third Party Advisory
VDB Entry
https://hackerone.com/reports/148300
Third Party Advisory
Exploit
VDB Entry
https://packetstormsecurity.com/files/142145/concrete5-8.1.0-Host-Header-Injection.html
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/41885/
Third Party Advisory
Exploit
VDB Entry