vendor:
OfficeScan
by:
John Page (aka hyp3rlinx)
7,5
CVSS
HIGH
Host Header Injection
N/A
CWE
Product Name: OfficeScan
Affected Version From: OfficeScan v11.0
Affected Version To: OfficeScan XG (12.0)*
Patch Exists: YES
Related CWE: CVE-2017-14087
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
TrendMicro OfficeScan XG Host Header Injection
Host header injection issue as "db_controller.php" relies on $_SERVER['HTTP_HOST'] which can be spoofed by client, instead of $_SERVER['SERVER_NAME']. In environments where caching is in place by making HTTP GET request with a poisoned HOST header webpages can potentially render arbitrary links that point to a malicious website.
Mitigation:
Vendor releases fixes / advisory