vendor:
Titsco Email Security Appliance (IronPort) C160
by:
Todor Donev
7.5
CVSS
HIGH
Header Injection
113
CWE
Product Name: Titsco Email Security Appliance (IronPort) C160
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
Cisco (Titsco) Email Security Appliance (IronPort) C160 Header ‘Host’ Injection
This exploit allows an attacker to inject a malicious 'Host' header into a request sent to a vulnerable Cisco (Titsco) Email Security Appliance (IronPort) C160 device. This can be used to bypass authentication and gain access to the device.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in a request header.