Schneider Electric OFS XML External Entity Injection Vulnerability
BID:62081
Info
Schneider Electric OFS XML External Entity Injection Vulnerability
| Bugtraq ID: | 62081 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 2013 12:00AM |
| Updated: | Aug 23 2013 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Schneider-Electric OFS 3.40 |
| Not Vulnerable: | |
Discussion
Schneider Electric OFS XML External Entity Injection Vulnerability
Schneider Electric OFS is prone to an XML External Entity injection vulnerability.
Local attacker can leverage this issue to obtain sensitive information or cause denial-of-service condition.
Schneider Electric OFS 3.40 and prior versions are vulnerable.
Schneider Electric OFS is prone to an XML External Entity injection vulnerability.
Local attacker can leverage this issue to obtain sensitive information or cause denial-of-service condition.
Schneider Electric OFS 3.40 and prior versions are vulnerable.
Solution / Fix
Schneider Electric OFS XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.