NeuroML Multiple Security Vulnerabilities
BID:70392
Info
NeuroML Multiple Security Vulnerabilities
| Bugtraq ID: | 70392 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2014 12:00AM |
| Updated: | Oct 10 2014 12:00AM |
| Credit: | Philipp Promeuschel |
| Vulnerable: |
NeuroML NeuroML 1.8.1 |
| Not Vulnerable: | |
Discussion
NeuroML Multiple Security Vulnerabilities
NeuroML is prone to the following security vulnerabilities:
1. An XML External Entity injection vulnerability
2. A cross-site scripting vulnerability
3. A path-disclosure vulnerability
4. A local file-include vulnerability
Attackers can exploit these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and execute arbitrary local scripts.
NeuroML 1.8.1 and prior are vulnerable.
NeuroML is prone to the following security vulnerabilities:
1. An XML External Entity injection vulnerability
2. A cross-site scripting vulnerability
3. A path-disclosure vulnerability
4. A local file-include vulnerability
Attackers can exploit these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and execute arbitrary local scripts.
NeuroML 1.8.1 and prior are vulnerable.