Vulnerabilities > CVE-2015-3000 - Resource Management Errors vulnerability in Sysaid

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
sysaid
CWE-399
exploit available

Summary

SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an XML document to (1) /agententry, (2) /rdsmonitoringresponse, or (3) /androidactions, aka an XML Entity Expansion (XEE) attack.

Vulnerable Configurations

Part Description Count
Application
Sysaid
4

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionSysAid Help Desk 14.4 - Multiple Vulnerabilities. CVE-2015-2993,CVE-2015-2994,CVE-2015-2995,CVE-2015-2996,CVE-2015-2997,CVE-2015-2998,CVE-2015-2999,CVE-2015-...
idEDB-ID:43885
last seen2018-01-25
modified2015-06-10
published2015-06-10
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43885/
titleSysAid Help Desk 14.4 - Multiple Vulnerabilities

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/132138/sysaidhelpdesk-execdos.txt
idPACKETSTORM:132138
last seen2016-12-05
published2015-06-03
reporterPedro Ribeiro
sourcehttps://packetstormsecurity.com/files/132138/SysAid-Help-Desk-14.4-Code-Execution-Denial-Of-Service-Traversal-SQL-Injection.html
titleSysAid Help Desk 14.4 Code Execution / Denial Of Service / Traversal / SQL Injection