Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-38751 PoC — ExponentCMS安全漏洞

Source
Associated Vulnerability
Title:ExponentCMS安全漏洞 (CVE-2021-38751)
Description:ExponentCMS是开源的一个网站内容管理系统,它允许网站所有者轻松创建和管理动态网站,而无需直接对网页进行编码或管理网站导航。 ExponentCMS 2.6及之前版本存在安全漏洞,该漏洞源于修改后的 HTTP 标头可以将网页上的链接更改为任意值,从而导致 MITM 可能的攻击向量。
Description
An HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value,leading to a possible attack vector for MITM.
File Snapshot

id: CVE-2021-38751 info: name: ExponentCMS <= 2.6 - Host Header Injection author: dwisiswant0 ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.