Belkin Wemo Home Automation Devices 'peerAddresses' API XML External Entity Injection Vulnerability
BID:65623
Info
Belkin Wemo Home Automation Devices 'peerAddresses' API XML External Entity Injection Vulnerability
| Bugtraq ID: | 65623 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-6948 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2014 12:00AM |
| Updated: | Mar 04 2014 01:51AM |
| Credit: | Mike Davis of IOActive. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Belkin Wemo Home Automation Devices 'peerAddresses' API XML External Entity Injection Vulnerability
Belkin Wemo Home Automation devices are prone to an XML External Entity injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attackers can exploit this issue to gain sensitive information of the system files.
Belkin Wemo Home Automation devices are prone to an XML External Entity injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attackers can exploit this issue to gain sensitive information of the system files.
Exploit / POC
Belkin Wemo Home Automation Devices 'peerAddresses' API XML External Entity Injection Vulnerability
Attackers can exploit this issue through readily available tools.
Attackers can exploit this issue through readily available tools.
Solution / Fix
Belkin Wemo Home Automation Devices 'peerAddresses' API XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Belkin Wemo Home Automation Devices 'peerAddresses' API XML External Entity Injection Vulnerability
References:
References: