Vulnerabilities > XML Injection (aka Blind XPath Injection)

DATE CVE VULNERABILITY TITLE RISK
2018-06-26 CVE-2018-1000526 XML Injection (aka Blind XPath Injection) vulnerability in Openpsa2 Openpsa
Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in Remote denial of service.
network
low complexity
openpsa2 CWE-91
5.0
2018-02-20 CVE-2016-6272 XML Injection (aka Blind XPath Injection) vulnerability in Epic Mychart
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp.
network
low complexity
epic CWE-91
5.0
2018-01-02 CVE-2017-1000452 XML Injection (aka Blind XPath Injection) vulnerability in Samlify Project Samlify
An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.
6.0
2017-09-14 CVE-2013-7429 XML Injection (aka Blind XPath Injection) vulnerability in Mapsplugin Googlemaps 3.0
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.
network
low complexity
mapsplugin CWE-91
critical
9.8
2017-07-21 CVE-2015-3932 XML Injection (aka Blind XPath Injection) vulnerability in Netlock Mokka
Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.
network
netlock CWE-91
6.8
2017-07-21 CVE-2015-3931 XML Injection (aka Blind XPath Injection) vulnerability in Microsec E-Szigno
Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.
network
microsec CWE-91
6.8
2017-07-17 CVE-2017-10603 XML Injection (aka Blind XPath Injection) vulnerability in Juniper Junos 15.1/15.1X53
An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user.
local
low complexity
juniper CWE-91
7.2
2017-05-22 CVE-2017-2171 XML Injection (aka Blind XPath Injection) vulnerability in Bestwebsoft products
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2, Custom Search prior to version 1.36, Donate prior to version 2.1.1, Email Queue prior to version 1.1.2, Error Log Viewer prior to version 1.0.6, Facebook Button prior to version 2.54, Featured Posts prior to version 1.0.1, Gallery Categories prior to version 1.0.9, Gallery prior to version 4.5.0, Google +1 prior to version 1.3.4, Google AdSense prior to version 1.44, Google Analytics prior to version 1.7.1, Google Captcha (reCAPTCHA) prior to version 1.28, Google Maps prior to version 1.3.6, Google Shortlink prior to version 1.5.3, Google Sitemap prior to version 3.0.8, Htaccess prior to version 1.7.6, Job Board prior to version 1.1.3, Latest Posts prior to version 0.3, Limit Attempts prior to version 1.1.8, LinkedIn prior to version 1.0.5, Multilanguage prior to version 1.2.2, PDF & Print prior to version 1.9.4, Pagination prior to version 1.0.7, Pinterest prior to version 1.0.5, Popular Posts prior to version 1.0.5, Portfolio prior to version 2.4, Post to CSV prior to version 1.3.1, Profile Extra prior to version 1.0.7.
4.3
2017-05-12 CVE-2017-5654 XML Injection (aka Blind XPath Injection) vulnerability in Apache Ambari 2.4.0/2.4.1/2.5.0
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
network
low complexity
apache CWE-91
5.0
2017-01-23 CVE-2016-5697 XML Injection (aka Blind XPath Injection) vulnerability in Onelogin Ruby-Saml
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
network
low complexity
onelogin CWE-91
5.0