exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 201 - 225 of 255 RSS Feed

XML Injection Files

Apache Shindig 2.5.0 XXE Injection
Posted Oct 22, 2013
Authored by Kousuke Ebihara

Apache Shindig PHP version 2.5.0 suffers from an XXE injection vulnerability.

tags | exploit, php, xxe
advisories | CVE-2013-4295
SHA-256 | 779177ad830a97195b2451720ea3c03e6dc8551bf514a289092bcaf78efa0131
Cisco Security Advisory 20130918-dcnm
Posted Sep 18, 2013
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - Cisco Prime Data Center Network Manager (DCNM) contains multiple vulnerabilities that could allow an unauthenticated, remote attacker to disclose file components, and access text files on an affected device. Various components of Cisco Prime DCNM are affected. These vulnerabilities can be exploited independently on the same device; however, a release that is affected by one of the vulnerabilities may not be affected by the others. Cisco Prime DCNM is affected by the following vulnerabilities: Cisco Prime DCNM Information Disclosure Vulnerability Cisco Prime DCNM Remote Command Execution Vulnerabilities Cisco Prime DCNM XML External Entity Injection Vulnerability Cisco has released free software updates that address these vulnerabilities. There are currently no workarounds that mitigate these vulnerabilities.

tags | advisory, remote, vulnerability, info disclosure, xxe
systems | cisco
SHA-256 | 59abee34c5117c85ecf0f7c23a0c36170f53170f33c1427314bb3d0f036af886
Spring Framework XXE Injection
Posted Aug 23, 2013
Authored by Alvaro Munoz

Spring Framework versions 3.x and 4.x suffer from an XML external entity (XXE) injection vulnerability.

tags | advisory, xxe
advisories | CVE-2013-4152
SHA-256 | 44db748efe1afb0144c46a27348301fabb29af09798bbf1a847a659236ae224d
Sybase EAServer XXE Injection
Posted Aug 11, 2013
Authored by MustLive

This is a supplement to the SA-20130719-0 SEC Consult advisory that notes an additional attack vector for an XXE injection vulnerability in Sybase EAServer.

tags | exploit, xxe
SHA-256 | 3cbd8730ac23a8caf0246048e716bcb96d05f72f025815f74e98ae2ed65f3b29
Ubuntu Security Notice USN-1904-2
Posted Jul 17, 2013
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1904-2 - USN-1904-1 fixed vulnerabilities in libxml2. The update caused a regression for certain users. This update fixes the problem. It was discovered that libxml2 would load XML external entities by default. If a user or automated system were tricked into opening a specially crafted document, an attacker could possibly obtain access to arbitrary files or cause resource consumption. This issue only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, and Ubuntu 12.10. Various other issues were also addressed.

tags | advisory, arbitrary, vulnerability, xxe
systems | linux, ubuntu
advisories | CVE-2013-0339, CVE-2013-2877
SHA-256 | 73ee61050460c5c1a204774c868ab1fa47667ad17da81dbf917de23f5248cb36
Joomla Googlemaps XSS / XML Injection / Path Disclosure / DoS
Posted Jul 17, 2013
Authored by MustLive

The Joomla Googlemaps plugin suffers from cross site scripting, path disclosure, denial of service, and XML injection vulnerabilities.

tags | exploit, denial of service, vulnerability, xss, xxe
SHA-256 | 165dc70f4d8846397f4d21ce1f9794a33e98cb8d13ea08baf7996288d00ca669
Ubuntu Security Notice USN-1904-1
Posted Jul 16, 2013
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1904-1 - It was discovered that libxml2 would load XML external entities by default. If a user or automated system were tricked into opening a specially crafted document, an attacker could possibly obtain access to arbitrary files or cause resource consumption. This issue only affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, and Ubuntu 12.10. It was discovered that libxml2 incorrectly handled documents that end abruptly. If a user or automated system were tricked into opening a specially crafted document, an attacker could possibly cause libxml2 to crash, resulting in a denial of service. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary, xxe
systems | linux, ubuntu
advisories | CVE-2013-0339, CVE-2013-2877, CVE-2013-0339, CVE-2013-2877
SHA-256 | cd859ab9c1529eb842030310fdae2e007f5f2c595e947035ccee976394f0e6e5
Ubuntu Security Notice USN-1901-1
Posted Jul 9, 2013
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1901-1 - Timothy D. Morgan discovered that Raptor would unconditionally load XML external entities. If a user were tricked into opening a specially crafted document in an application linked against Raptor, an attacker could possibly obtain access to arbitrary files on the user's system or potentially execute arbitrary code with the privileges of the user invoking the program.

tags | advisory, arbitrary, xxe
systems | linux, ubuntu
advisories | CVE-2012-0037
SHA-256 | 129bfa80ff19162520bf13eed9fe89bfddd3574089068101f024e5bd08c06df6
Mandriva Linux Security Advisory 2013-189
Posted Jul 2, 2013
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2013-189 - A denial of service flaw was found in the way Wordpress, a blog tool and publishing platform, performed hash computation when checking password for password protected blog posts. A remote attacker could provide a specially-crafted input that, when processed by the password checking mechanism of Wordpress would lead to excessive CPU consumption. Inadequate SSRF protection for HTTP requests where the user can provide a URL can allow for attacks against the intranet and other sites. This is a continuation of work related to which was specific to SSRF in pingback requests and was fixed in 3.5.1. Inadequate checking of a user's capabilities could allow them to publish posts when their user role should not allow for it; and to assign posts to other authors. Inadequate escaping allowed an administrator to trigger a cross-site scripting vulnerability through the uploading of media files and plugins. The processing of an oEmbed response is vulnerable to an XXE. If the uploads directory is not writable, error message data returned via XHR will include a full path to the directory. Content Spoofing in the MoxieCode MoxiePlayer project. Cross-domain XSS in SWFUpload.

tags | advisory, remote, web, denial of service, spoof, xss, xxe
systems | linux, mandriva
advisories | CVE-2013-2173, CVE-2013-2199, CVE-2013-2200, CVE-2013-2201, CVE-2013-2202, CVE-2013-2203, CVE-2013-2204, CVE-2013-2205
SHA-256 | 3e869d97c655df62325e93db12a848e89fa7b202bd9d44aa6cf2f3bdfc8b51b0
Red Hat Security Advisory 2013-0993-01
Posted Jun 27, 2013
Authored by Red Hat | Site access.redhat.com

Red Hat Security Advisory 2013-0993-01 - OpenStack Swift is a highly available, distributed, eventually consistent object/blob store. An XML injection flaw in OpenStack Swift could allow remote attackers to manipulate the contents of XML responses via specially-crafted data. This could be used to trigger a denial of service.

tags | advisory, remote, denial of service, xxe
systems | linux, redhat
advisories | CVE-2013-2161
SHA-256 | 28a8b98698ba460b04f7bcbc2c2b29b15adacb9c2f421378f5d59be53638b7c8
IceWarp Mail Server 10.4.5 XSS / XXE Injection
Posted Jun 25, 2013
Authored by V. Paulikas | Site sec-consult.com

IceWarp Mail Server versions 10.4.5 and below suffer from cross site scripting and XML external entity injection vulnerabilities.

tags | exploit, vulnerability, xss, xxe
SHA-256 | 84d292ec76f89464eea4d17baff572a4b0ef0577f2fb641e3f8541b6a69f2f43
CTERA Portal 3.1 XSS / XXE Injection / Bypass
Posted Jun 5, 2013
Authored by Stefan Streichsbier | Site sec-consult.com

CTERA Portal version 3.1 suffers from an out of date Tomcat instance, account locking bypass, XXE injection, and cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss, xxe
SHA-256 | e9e827e5803c11cbf3bb5a96c728346d774b0d415eac2e711b14038e1f907e29
WordPress Advanced XML Reader 0.3.4 XXE Injection
Posted May 2, 2013
Authored by system_meltdown

WordPress Advanced XML Reader plugin version 0.3.4 suffers from a XXE (XML eXternal Entity) injection vulnerability.

tags | exploit, xxe
SHA-256 | 8f00f9b3232481b2651bd135bbb4cc1f273adbf09d9d0da522f46d08d53f898b
Mandriva Linux Security Advisory 2013-156
Posted Apr 29, 2013
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2013-156 - ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity vulnerability. The updated packages have been patched to correct this issue.

tags | advisory, remote, web, denial of service, arbitrary, xxe
systems | linux, mandriva
advisories | CVE-2013-1915
SHA-256 | 686354a3dac07edc7796a50d9ab3acf3cac39229d4912db2ea0ab6d44023c774
Mandriva Linux Security Advisory 2013-114
Posted Apr 11, 2013
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2013-114 - ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory. The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity issue in the soap_xmlParseFile and soap_xmlParseMemory functions. Various other issues have also been addressed.

tags | advisory, remote, arbitrary, php, xxe
systems | linux, mandriva
advisories | CVE-2013-1635, CVE-2013-1643
SHA-256 | 300d6d024575289b1802726ba11c43c279ed42aad1d023b478f6e96f8e3ae2d3
Debian Security Advisory 2659-1
Posted Apr 11, 2013
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2659-1 - Timur Yunusov and Alexey Osipov from Positive Technologies discovered that the XML files parser of ModSecurity, an Apache module whose purpose is to tighten the Web application security, is vulnerable to XML external entities attacks. A specially-crafted XML file provided by a remote attacker, could lead to local file disclosure or excessive resources (CPU, memory) consumption when processed.

tags | advisory, remote, web, local, xxe
systems | linux, debian
advisories | CVE-2013-1915
SHA-256 | 2ecf19e474f3d84104001f515f49ee5b01e068c895b4d46153fcc73ed4e1f6ef
Ubuntu Security Notice USN-1761-1
Posted Mar 14, 2013
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1761-1 - It was discovered that PHP incorrectly handled XML external entities in SOAP WSDL files. A remote attacker could use this flaw to read arbitrary files off the server.

tags | advisory, remote, arbitrary, php, xxe
systems | linux, ubuntu
advisories | CVE-2013-1643
SHA-256 | a139f03fd0b8a9c748ca3fca8449ab784e6431886e31fd02762b622672ee72b4
GroundWork Monitor Enterprise 6.7.0 XSS / Disclosure / Command Execution
Posted Mar 8, 2013
Authored by Johannes Greil | Site sec-consult.com

GroundWork Monitor Enterprise version 6.7.0 suffers from insufficient authentication, file disclosure, file modification, cross site scripting, XML external entity injection, command injection, and various other vulnerabilities. Detailed proof of concepts were removed by the author because GroundWork is refusing to fix the underlying security issues.

tags | advisory, vulnerability, xss, proof of concept, xxe
SHA-256 | 96c7a6d3d01751ea9ff17e2fa08b0d6e1ef1b0d0d735f08fb7964d7f9ea4c83e
Ubuntu Security Notice USN-1712-1
Posted Jan 31, 2013
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1712-1 - It was discovered that Inkscape incorrectly handled XML external entities in SVG files. If a user were tricked into opening a specially-crafted SVG file, Inkscape could possibly include external files in drawings, resulting in information disclosure. It was discovered that Inkscape attempted to open certain files from the /tmp directory instead of the current directory. A local attacker could trick a user into opening a different file than the one that was intended. This issue only applied to Ubuntu 11.10, Ubuntu 12.04 LTS and Ubuntu 12.10. Various other issues were also addressed.

tags | advisory, local, info disclosure, xxe
systems | linux, ubuntu
advisories | CVE-2012-5656, CVE-2012-6076, CVE-2012-5656, CVE-2012-6076
SHA-256 | ad9711511dcca224388d073b2dfe23803a095bc6b5187c2009d479f41de3f37d
F5 BIG-IP 11.2.0 XML External Entity Injection
Posted Jan 22, 2013
Authored by S. Viehbock | Site sec-consult.com

F5 BIG-IP versions 11.2.0 and below suffer from an XML external entity injection (XXE) vulnerability.

tags | exploit, xxe
advisories | CVE-2012-2997
SHA-256 | eed88f6727e8539cfd0581fa3d650e62fcb1404306be009618a1f266887154ab
IBM DB2 LUW 9.x / 10.1 XML File Disclosure
Posted Oct 5, 2012
Authored by Martin Rakhmanov | Site appsecinc.com

Team SHATTER Security Advisory - Two system stored procedures executable by PUBLIC allow reading of files with xml extensions in IBM DB2 LUW versions 9.1, 9.5, 9.7, and 10.1.

tags | advisory, info disclosure, xxe
advisories | CVE-2012-2196
SHA-256 | 107b4fda80eb2d3a4a4a72644c82a7c887c11de47730435f9aa331d4906b0061
Ektron CMS 8.5.0 File Upload / XXE Injection
Posted Sep 6, 2012
Authored by Phil Taylor | Site senseofsecurity.com.au

Ektron CMS version 8.5.0 suffers from unauthenticated file upload and XXE injection vulnerabilities.

tags | exploit, vulnerability, file upload, xxe
SHA-256 | aec2ac7f32fa1685fd5e487de3e2ea551d1c03b5a65c07c2695b12fd0654d18e
CakePHP / Squiz CMS XXE Injection
Posted Aug 12, 2012
Authored by MustLive

CakePHP and Squiz CMS suffer from XXE injection vulnerabilities.

tags | exploit, vulnerability, xxe
SHA-256 | 961339f6ca18d70df5c08cf52ba52dcf3e959a21197fa995450430621e4c7f3f
Zend Framework XXE Injection
Posted Aug 11, 2012
Authored by MustLive

Zend Framework suffers from local file disclosure via XXE injection.

tags | exploit, local, xxe
SHA-256 | eb7c6a34464370c4bd7ce549e0dfb4ef4024f3518120db41e18e374bcccf17c4
CakePHP 2.2.0-RC2 XXE Injection
Posted Jul 16, 2012
Authored by Pawel Wylecial

CakePHP versions 2.x through 2.2.0-RC2 suffer from a XXE injection vulnerability.

tags | exploit, xxe
SHA-256 | 54d1c4dda8e08667e5b5c0da52af3bfbbf429c685ad10b6ddb43edebd154ffb5
Page 9 of 11
Back7891011Next

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    29 Files
  • 21
    Aug 21st
    42 Files
  • 22
    Aug 22nd
    26 Files
  • 23
    Aug 23rd
    25 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    21 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close