Vulnerabilities > CVE-2017-9095 - XXE vulnerability in Divinglog Diving LOG
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description | Diving Log 6.0 - XML External Entity Injection. CVE-2017-9095. Local exploit for Windows platform |
file | exploits/windows/local/43187.txt |
id | EDB-ID:43187 |
last seen | 2017-11-28 |
modified | 2017-11-27 |
platform | windows |
port | |
published | 2017-11-27 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/43187/ |
title | Diving Log 6.0 - XML External Entity Injection |
type | local |
Packetstorm
data source | https://packetstormsecurity.com/files/download/145153/divinglog6-xxe.txt |
id | PACKETSTORM:145153 |
last seen | 2017-12-01 |
published | 2017-11-27 |
reporter | Trent Gordon |
source | https://packetstormsecurity.com/files/145153/Diving-Log-6.0-XML-External-Entity-Injection.html |
title | Diving Log 6.0 XML External Entity Injection |