Yokogawa FAST/TOOLS CVE-2014-7251 XML External Entity Injection Vulnerability
BID:71379
Info
Yokogawa FAST/TOOLS CVE-2014-7251 XML External Entity Injection Vulnerability
| Bugtraq ID: | 71379 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7251 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 28 2014 12:00AM |
| Updated: | Nov 28 2014 12:00AM |
| Credit: | Timur Yunusov, Alexey Osipov and Ilya Karpov of Positive Technologies. |
| Vulnerable: |
Yokogawa FAST/TOOLS R9.05 Yokogawa FAST/TOOLS R9.01 |
| Not Vulnerable: |
Yokogawa FAST/TOOLS R9.05-SP2 |
Discussion
Yokogawa FAST/TOOLS CVE-2014-7251 XML External Entity Injection Vulnerability
Yokogawa FAST/TOOLS is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Yokogawa FAST/TOOLS R9.01 through R9.05 are vulnerable.
Yokogawa FAST/TOOLS is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Yokogawa FAST/TOOLS R9.01 through R9.05 are vulnerable.
Exploit / POC
Yokogawa FAST/TOOLS CVE-2014-7251 XML External Entity Injection Vulnerability
An attacker can exploit this issue using readily available tools..
An attacker can exploit this issue using readily available tools..
Solution / Fix
Yokogawa FAST/TOOLS CVE-2014-7251 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Yokogawa FAST/TOOLS CVE-2014-7251 XML External Entity Injection Vulnerability
References:
References: