SOAPpy XML External Entity Injection and Denial of Service Vulnerabilities
BID:67216
Info
SOAPpy XML External Entity Injection and Denial of Service Vulnerabilities
| Bugtraq ID: | 67216 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3242 CVE-2014-3243 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2014 12:00AM |
| Updated: | May 07 2014 10:53AM |
| Credit: | feer james |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SOAPpy XML External Entity Injection and Denial of Service Vulnerabilities
SOAPpy is prone to an XML External Entity injection vulnerability and a denial-of-service vulnerability.
Attackers can exploit these issues to obtain potentially sensitive information or cause denial-of-service conditions. This may lead to further attacks.
SOAPpy 0.12.5 is vulnerable; other versions may also be affected.
SOAPpy is prone to an XML External Entity injection vulnerability and a denial-of-service vulnerability.
Attackers can exploit these issues to obtain potentially sensitive information or cause denial-of-service conditions. This may lead to further attacks.
SOAPpy 0.12.5 is vulnerable; other versions may also be affected.
Exploit / POC
SOAPpy XML External Entity Injection and Denial of Service Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
SOAPpy XML External Entity Injection and Denial of Service Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SOAPpy XML External Entity Injection and Denial of Service Vulnerabilities
References:
References: