Vulnerabilities > CVE-2017-9095 - XXE vulnerability in Divinglog Diving LOG

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
divinglog
CWE-611
exploit available

Summary

XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.

Vulnerable Configurations

Part Description Count
Application
Divinglog
53

Exploit-Db

descriptionDiving Log 6.0 - XML External Entity Injection. CVE-2017-9095. Local exploit for Windows platform
fileexploits/windows/local/43187.txt
idEDB-ID:43187
last seen2017-11-28
modified2017-11-27
platformwindows
port
published2017-11-27
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43187/
titleDiving Log 6.0 - XML External Entity Injection
typelocal

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/145153/divinglog6-xxe.txt
idPACKETSTORM:145153
last seen2017-12-01
published2017-11-27
reporterTrent Gordon
sourcehttps://packetstormsecurity.com/files/145153/Diving-Log-6.0-XML-External-Entity-Injection.html
titleDiving Log 6.0 XML External Entity Injection