Vulnerabilities > CVE-2015-2125 - XXE vulnerability in HP Webinspect
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | HP WebInspect <= 10.4 XML External Entity Injection. CVE-2015-2125. Webapps exploit for xml platform |
file | exploits/xml/webapps/37250.txt |
id | EDB-ID:37250 |
last seen | 2016-02-04 |
modified | 2015-06-10 |
platform | xml |
port | |
published | 2015-06-10 |
reporter | Jakub Palaczynski |
source | https://www.exploit-db.com/download/37250/ |
title | HP WebInspect <= 10.4 XML External Entity Injection |
type | webapps |
Nessus
NASL family | Windows |
NASL id | HP_WEBINSPECT_SSRT102038.NASL |
description | The version of HP WebInspect installed on the remote Windows host is affected by an unauthorized information disclosure vulnerability due to an XML external entity injection flaw that is triggered during the parsing of XML data. A remote attacker can exploit this, via a malicious website scanned by HP WebInspect, to read arbitrary system files. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 84194 |
published | 2015-06-15 |
reporter | This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/84194 |
title | HP WebInspect XXE Unauthorized Information Disclosure |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/132280/hpwebinspect-xxe.txt |
id | PACKETSTORM:132280 |
last seen | 2016-12-05 |
published | 2015-06-12 |
reporter | Jakub Palaczynski |
source | https://packetstormsecurity.com/files/132280/HP-WebInspect-10.4-XML-External-Entity.html |
title | HP WebInspect 10.4 XML External Entity |