Vulnerabilities > CVE-2017-8918 - XXE vulnerability in Blackwave Dive Assistant 8.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
blackwave
CWE-611
exploit available

Summary

XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.

Vulnerable Configurations

Part Description Count
Application
Blackwave
1

Exploit-Db

idEDB-ID:42000
last seen2018-11-30
modified2017-05-12
published2017-05-12
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/42000
titleDive Assistant Template Builder 8.0 - XML External Entity Injection