7.5
CVSSv3

CVE-2017-14523

Published: 26/01/2018 Updated: 17/05/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack

Vulnerable Product Search on Vulmon Subscribe to Product

wondercms wondercms 2.3.1

Exploits

# Exploit Title: Wonder CMS 231 Host Header Injection # Date: 30-01-2018 # Exploit Author: Samrat Das # Contact: twittercom/Samrat_Das93 # Website: securitywarrior9blogspotin/ # Vendor Homepage: wwwwondercmscom/ # Version: 231 # CVE : CVE-2017-14523 # Category: Webapp CMS 1 Description The application allows illeg ...
Wonder CMS version 231 suffers from a host header injection vulnerability ...