XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
References
Link | Resource |
---|---|
https://thenopsled.com/Exploit-DB%20Writeup.txt | Exploit Third Party Advisory |
Configurations
Information
Published : 2017-09-12 11:29
Updated : 2017-09-21 11:46
NVD link : CVE-2017-8918
Mitre link : CVE-2017-8918
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
blackwave
- dive_assistant