XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
References
Link | Resource |
---|---|
https://thenopsled.com/Exploit-DB%20Writeup.txt | Exploit Third Party Advisory |
https://thenopsled.com/Exploit-DB%20Writeup.txt | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 03:34
Type | Values Removed | Values Added |
---|---|---|
References | () https://thenopsled.com/Exploit-DB%20Writeup.txt - Exploit, Third Party Advisory |
Information
Published : 2017-09-12 18:29
Updated : 2024-11-21 03:34
NVD link : CVE-2017-8918
Mitre link : CVE-2017-8918
CVE.ORG link : CVE-2017-8918
JSON object : View
Products Affected
blackwave
- dive_assistant
CWE
CWE-611
Improper Restriction of XML External Entity Reference