435
VMScore

CVE-2016-0400

Published: 02/07/2016 Updated: 03/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 prior to 7.1.0.3, 7.1.1 prior to 7.1.1.1, 8.5 prior to 8.5.0.3, and 8.6 prior to 8.6.0.8 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere extreme scale 8.6.0.2

ibm websphere extreme scale 8.6.0.1

ibm websphere extreme scale 7.1.0.2

ibm websphere extreme scale 8.6.0.7

ibm websphere extreme scale 8.6.0.0

ibm websphere extreme scale 8.5.0

ibm websphere extreme scale 8.6.0.6

ibm websphere extreme scale 8.6.0.5

ibm websphere extreme scale 8.5.0.2

ibm websphere extreme scale 8.5.0.1

ibm websphere extreme scale 8.6.0.4

ibm websphere extreme scale 8.6.0.3

ibm websphere extreme scale 7.1.1

ibm websphere extreme scale 7.1.0

Exploits

/* # Exploit Title: Elevation of privilege on Windows 7 SP1 x86 # Date: 28/06-2016 # Exploit Author: @blomster81 # Vendor Homepage: wwwmicrosoftcom # Version: Windows 7 SP1 x86 # Tested on: Windows 7 SP1 x86 # CVE : 2016-0400 MS16-014 EoP PoC created from githubcom/Rootkitsmm/cve-2016-0040/blob/master/poccc Spawns CMDexe with SYSTEM ...