CVE-2017-11706
Last modified
CVE-2017-11706 is a vulnerability of currently unknown severity. The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the lack of SSL. NOTE: the vendor response, before the application was changed to enable SSL logins, was "At the moment that is an accepted risk. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the lack of SSL. NOTE: the vendor response, before the application was changed to enable SSL logins, was "At the moment that is an accepted risk. We only have https on the checkout part of the site."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Boozt | Boozt | <= 2.3.3 |
References
- https://hackerone.com/reports/166712Third Party Advisory
- https://hackerone.com/reports/166712Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11706?
How severe is CVE-2017-11706?
How do I fix CVE-2017-11706?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11697The __hash_open function in hash.c:229 in Mozilla Network Se…
- CVE-2017-11698Heap-based buffer overflow in the __get_page function in lib…
- CVE-2017-1170IBM WebSphere Commerce Enterprise, Professional, Express, an…
- CVE-2017-11703A memory leak vulnerability was found in the function parseS…
- CVE-2017-11704A heap-based buffer over-read was found in the function deco…
- CVE-2017-11705A memory leak was found in the function parseSWF_SHAPEWITHST…
- CVE-2017-1171The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 conta…
- CVE-2017-11714psi/ztoken.c in Artifex Ghostscript 9.21 mishandles referenc…
- CVE-2017-11715job/uploadfile_save.php in MetInfo through 5.3.17 blocks the…
- CVE-2017-11716MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
- CVE-2017-11717MetInfo through 5.3.17 accepts the same CAPTCHA response for…
- CVE-2017-11718There is URL Redirector Abuse in MetInfo through 5.3.17 via …
Are you affected by CVE-2017-11706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
