Scalix Web Access XML External Entity Injection Vulnerability
BID:70857
Info
Scalix Web Access XML External Entity Injection Vulnerability
| Bugtraq ID: | 70857 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2014 12:00AM |
| Updated: | Oct 31 2014 12:00AM |
| Credit: | R. Giruckas, and A. Kolmann |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Scalix Web Access XML External Entity Injection Vulnerability
Scalix Web Access is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information. This may lead to further attacks.
Scalix Web Access versions 11.4.6.12377, and 12.2.0.14697 are vulnerable.
Scalix Web Access is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information. This may lead to further attacks.
Scalix Web Access versions 11.4.6.12377, and 12.2.0.14697 are vulnerable.
Exploit / POC
Scalix Web Access XML External Entity Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Scalix Web Access XML External Entity Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Scalix Web Access XML External Entity Injection Vulnerability
References:
References: