JobScheduler CVE-2014-5392 XML External Entity Injection Vulnerability
BID:69664
Info
JobScheduler CVE-2014-5392 XML External Entity Injection Vulnerability
| Bugtraq ID: | 69664 |
| Class: | Design Error |
| CVE: |
CVE-2014-5392 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2014 12:00AM |
| Updated: | Sep 01 2014 12:00AM |
| Credit: | Christian Schneider |
| Vulnerable: |
SOS GmbH JobScheduler 1.7 SOS GmbH JobScheduler 1.6 |
| Not Vulnerable: |
SOS GmbH JobScheduler 1.7.4241 SOS GmbH JobScheduler 1.6.4246 |
Discussion
JobScheduler CVE-2014-5392 XML External Entity Injection Vulnerability
JobScheduler is prone to an XML External Entity injection vulnerability.
An attacker can exploit this issue to cause denial-of-service condition, or gain access to sensitive information. This may lead to further attacks.
The following versions are affected:
JobScheduler 1.6.x versions prior to 1.6.4246
JobScheduler 1.7.x versions prior to 1.7.4241
JobScheduler is prone to an XML External Entity injection vulnerability.
An attacker can exploit this issue to cause denial-of-service condition, or gain access to sensitive information. This may lead to further attacks.
The following versions are affected:
JobScheduler 1.6.x versions prior to 1.6.4246
JobScheduler 1.7.x versions prior to 1.7.4241