.. / CVE-2017-4011

Exploit for McAfee Network Data Loss Prevention 9.3.x - Cross-Site Scripting (CVE-2017-4011)

Description:

McAfee Network Data Loss Prevention User-Agent 9.3.x contains a cross-site scripting vulnerability which allows remote attackers to get session/cookie information via modification of the HTTP request.

Nuclei Template

View the template here CVE-2017-4011.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2017/CVE-2017-4011.yaml
Copy

References:

http://www.securitytracker.com/id/1038523
https://nvd.nist.gov/vuln/detail/CVE-2017-4011
https://github.com/ARPSyndicate/kenzer-templates
https://medium.com/@david.valles/cve-2017-4011-reflected-xss-found-in-mcafee-network-data-loss-prevention-ndlp-9-3-x-cf20451870ab
https://kc.mcafee.com/corporate/index?page=content&id=SB10198