Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
BID:100558
CVE-2016-5795 |Info
Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
| Bugtraq ID: | 100558 |
| Class: | Input Validation Error |
| CVE: |
CVE-2016-5795 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2017 12:00AM |
| Updated: | Aug 31 2017 12:00AM |
| Credit: | Evgeny Ermakov from Kaspersky Lab. |
| Vulnerable: |
Automated Logic Corporation (ALC) WebCTRL 6.5 Automated Logic Corporation (ALC) WebCTRL 6.1 Automated Logic Corporation (ALC) WebCTRL 6.0 Automated Logic Corporation (ALC) WebCTRL 5.5 Automated Logic Corporation (ALC) WebCTRL 5.2 Automated Logic Corporation (ALC) SiteScan Web 6.5 Automated Logic Corporation (ALC) SiteScan Web 6.1 Automated Logic Corporation (ALC) SiteScan Web 5.5 Automated Logic Corporation (ALC) SiteScan Web 5.2 Automated Logic Corporation (ALC) i-Vu 6.5 Automated Logic Corporation (ALC) i-Vu 6.1 Automated Logic Corporation (ALC) i-Vu 6.0 Automated Logic Corporation (ALC) i-Vu 5.5 Automated Logic Corporation (ALC) i-Vu 5.2 |
| Not Vulnerable: | |
Discussion
Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
Multiple Automated Logic Corporation are prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or cause denial-of-service condition.
The following products and versions are affected :
ALC Liebert SiteScan Web Version 6.5 and prior
ALC WebCTRL Version 6.5 and prior
ALC Carrier i-Vu Version 6.5 and prior
Multiple Automated Logic Corporation are prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or cause denial-of-service condition.
The following products and versions are affected :
ALC Liebert SiteScan Web Version 6.5 and prior
ALC WebCTRL Version 6.5 and prior
ALC Carrier i-Vu Version 6.5 and prior
Exploit / POC
Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Automated Logic Corporation CVE-2016-5795 XML External Entity Injection Vulnerability
References:
References:
- Automated Logic Corporation (ALC) Homepage (Automated Logic Corporation (ALC))
- ICSA-17-150-01) Automated Logic Corporation ALC WebCTRL, Liebert SiteScan, Carri (CERT)