CVE-2018-11652 is a critical CSV Injection vulnerability affecting Nikto 2.1.6 and earlier, allowing remote attackers to execute arbitrary OS commands. This high-severity flaw (CVSS 9.8) enables unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) by injecting malicious content into the Server field of an HTTP response, which is then directly written to a CSV report. While not listed in CISA KEV, a public exploit (EDB-44899) exists, and the vulnerability has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.6CPE matchmatch criteria | cpe:2.3:a:cirt.net:nikto:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.