Vulnerabilities > CVE-2015-3623 - Unspecified vulnerability in Qlik Qlikview
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Qlikview <= 11.20 SR11 - Blind XXE Injection Vulnerability. CVE-2015-3623. Webapps exploit for xml platform |
file | exploits/xml/webapps/38118.txt |
id | EDB-ID:38118 |
last seen | 2016-02-04 |
modified | 2015-09-09 |
platform | xml |
port | |
published | 2015-09-09 |
reporter | Alex Haynes |
source | https://www.exploit-db.com/download/38118/ |
title | Qlikview <= 11.20 SR11 - Blind XXE Injection Vulnerability |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | QLIKVIEW_SERVER_11_20_SR12.NASL |
description | The version of QlikView Server running on the remote host is 11.20 prior to 11.20 SR12. It is, therefore, affected by an XML external entity (XXE) injection vulnerability, specifically DTD parameter injection, in the /AccessPoint.aspx script due to an incorrectly configured XML parser accepting XML external entities from untrusted sources. An unauthenticated, remote attacker can exploit this, via crafted XML data, to conduct server-side request forgery (SSRF) attacks and to read arbitrary files. Note that Nessus has not tested for this issue but has instead relied only on the application |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 91782 |
published | 2016-06-23 |
reporter | This script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/91782 |
title | QlikView Server AccessPoint XML External Entity Injection |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/133499/qlikview-xxe.txt |
id | PACKETSTORM:133499 |
last seen | 2016-12-05 |
published | 2015-09-09 |
reporter | Alex Haynes |
source | https://packetstormsecurity.com/files/133499/Qlikview-11.20-SR4-Blind-XXE-Injection.html |
title | Qlikview 11.20 SR4 Blind XXE Injection |
References
- http://packetstormsecurity.com/files/133499/Qlikview-11.20-SR4-Blind-XXE-Injection.html
- http://packetstormsecurity.com/files/133499/Qlikview-11.20-SR4-Blind-XXE-Injection.html
- http://www.securityfocus.com/archive/1/536411/100/0/threaded
- http://www.securityfocus.com/archive/1/536411/100/0/threaded
- https://www.exploit-db.com/exploits/38118/
- https://www.exploit-db.com/exploits/38118/