Vulnerability record · CVE-2018-11652 · published 1 June 2018
CVE-2018-11652: Cirt.net nikto csv injection vulnerability
CCirt.Net · Nikto
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
Description
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/sullo/nikto/commit/e759b3300aace5314fe3d30800c8bd83c81c29f7 | PatchThird Party Advisory |
| https://www.exploit-db.com/exploits/44899/ | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/sullo/nikto/commit/e759b3300aace5314fe3d30800c8bd83c81c29f7 | PatchThird Party Advisory |
| https://www.exploit-db.com/exploits/44899/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-11652 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2018-11652), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.