Vulnerabilities > CVE-2017-9095 - XXE vulnerability in Divinglog Diving LOG 6.0
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Diving Log 6.0 - XML External Entity Injection. CVE-2017-9095. Local exploit for Windows platform |
file | exploits/windows/local/43187.txt |
id | EDB-ID:43187 |
last seen | 2017-11-28 |
modified | 2017-11-27 |
platform | windows |
port | |
published | 2017-11-27 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/43187/ |
title | Diving Log 6.0 - XML External Entity Injection |
type | local |
Packetstorm
data source | https://packetstormsecurity.com/files/download/145153/divinglog6-xxe.txt |
id | PACKETSTORM:145153 |
last seen | 2017-12-01 |
published | 2017-11-27 |
reporter | Trent Gordon |
source | https://packetstormsecurity.com/files/145153/Diving-Log-6.0-XML-External-Entity-Injection.html |
title | Diving Log 6.0 XML External Entity Injection |