Vulnerabilities > CVE-2017-7457 - XXE vulnerability in Moxa Mx-Aopc Server 1.5

047910
CVSS 5.0 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
moxa
CWE-611
exploit available

Summary

XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.

Vulnerable Configurations

Part Description Count
Application
Moxa
1

Exploit-Db

descriptionMoxa MX AOPC-Server 1.5 - XML External Entity Injection. CVE-2017-7457. Remote exploit for Windows platform
fileexploits/windows/remote/41852.txt
idEDB-ID:41852
last seen2017-04-10
modified2017-04-10
platformwindows
port
published2017-04-10
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/41852/
titleMoxa MX AOPC-Server 1.5 - XML External Entity Injection
typeremote

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/142076/MOXA-MX-AOPC-SERVER-v1.5-XML-EXTERNAL-ENTITY.txt
idPACKETSTORM:142076
last seen2017-04-11
published2017-04-10
reporterhyp3rlinx
sourcehttps://packetstormsecurity.com/files/142076/Moxa-MX-AOPC-UA-Server-1.5-XML-Injection.html
titleMoxa MX-AOPC UA Server 1.5 XML Injection