Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-11706

The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the lack of SSL. NOTE: the vendor response, before the application was changed to enable SSL logins, was "At the moment that is an accepted risk. We only have https on the checkout part of the site."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-11706
  • Boozt » Boozt » Version: 2.3.3
    cpe:2.3:a:boozt:boozt:2.3.3


Contact Us

Shodan ® - All rights reserved