Vulnerabilities > CVE-2017-8918 - XXE vulnerability in Blackwave Dive Assistant 8.0

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
blackwave
CWE-611
exploit available

Summary

XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.

Vulnerable Configurations

Part Description Count
Application
Blackwave
1

Exploit-Db

idEDB-ID:42000
last seen2018-11-30
modified2017-05-12
published2017-05-12
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/42000
titleDive Assistant Template Builder 8.0 - XML External Entity Injection