Menu

Search for hundreds of thousands of exploits

"Wonder CMS 2.3.1 - 'Host' Header Injection"

Author

Exploit author

"Samrat Das"

Platform

Exploit platform

php

Release date

Exploit published date

2018-02-05

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
# Exploit Title: Wonder CMS 2.3.1 Host Header Injection
# Date: 30-01-2018
# Exploit Author: Samrat Das
# Contact: http://twitter.com/Samrat_Das93
# Website: https://securitywarrior9.blogspot.in/
# Vendor Homepage: https://www.wondercms.com/
# Version: 2.3.1
# CVE : CVE-2017-14523
# Category: Webapp CMS

1. Description

The application allows illegitimate host header manipulation and leads to aribtary web page re-direction. This can also lead to severe attacks such as password reset or web cache poisoning

 
   
2. Proof of Concept

Intercept any web request of cms using a proxy tool. 
Change the http host header to: 
POST / HTTP/1.1
Host: google.com

You can observe the page being re-directed and the Location header changed in response to: http://www.google.com/ 
   
3. Solution:
   
To Mitigate host header injections allows only a whitelist of allowed hostnames.
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2018-06-25 "Intex Router N-150 - Cross-Site Request Forgery (Add Admin)" webapps hardware "Samrat Das"
2018-06-25 "Intex Router N-150 - Arbitrary File Upload" webapps hardware "Samrat Das"
2018-04-02 "Frog CMS 0.9.5 - Cross-Site Request Forgery (Add User)" webapps php "Samrat Das"
2018-02-19 "October CMS < 1.0.431 - Cross-Site Scripting" webapps php "Samrat Das"
2018-02-16 "Front Accounting ERP 2.4.3 - Cross-Site Request Forgery" webapps php "Samrat Das"
2018-02-05 "Wonder CMS 2.3.1 - 'Host' Header Injection" webapps php "Samrat Das"
2018-02-05 "Wonder CMS 2.3.1 - Unrestricted File Upload" webapps php "Samrat Das"
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.