Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xml injection vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-36359
OrbiTeam BSCW Classic prior to 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection because reportlab\platypus\paraparser.py (reached via bscw.cgi op=_editfolder.EditFolder) calls eval on attacker-supplied Python code. This is fixed in 5.0.12, 5....
Bscw Bscw Classic
NA
CVE-2013-0175
multi_xml gem 0.5.2 for Ruby, as used in Grape prior to 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote malicious users to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory a...
Erik Michaels-ober Multi Xml 0.5.2
Grape Project Grape 0.2.4
Grape Project Grape 0.2.0
Grape Project Grape 0.1.5
Grape Project Grape 0.1.4
Grape Project Grape 0.2.2
Grape Project Grape 0.2.3
Grape Project Grape 0.2.5
Grape Project Grape 0.1.2
Grape Project Grape 0.1.3
Erik Michaels-ober Multi Xml 0.5.2
Grape Project Grape 0.2.1
Grape Project Grape 0.1.1
Grape Project Grape 0.1.0
NA
CVE-2012-2997
XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 up to and including 10.2.4 and 11.0.0 up to and including 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file.
F5 Big-ip Configuration Utility 10.0.0
F5 Big-ip Configuration Utility 10.2.4
F5 Big-ip Configuration Utility 11.0.0
F5 Big-ip Configuration Utility 11.2.1
1 EDB exploit
9.8
CVSSv3
CVE-2014-0030
The XML-RPC protocol support in Apache Roller prior to 5.0.3 allows malicious users to conduct XML External Entity (XXE) attacks via unspecified vectors.
Apache Roller 4.0.1
Apache Roller 3.1
Apache Roller 4.0
Apache Roller 5.0
Apache Roller 5.0.1
Apache Roller 5.0.2
1 EDB exploit
9.1
CVSSv3
CVE-2021-37425
Altova MobileTogether Server prior to 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
Altova Mobiletogether Server
Altova Mobiletogether Server 7.3
7.5
CVSSv3
CVE-2019-10718
BlogEngine.NET 3.3.7.0 and previous versions allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.
Dotnetblogengine Blogengine.net
7.4
CVSSv3
CVE-2017-9355
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote malicious users to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.
Subsonic Subsonic 6.1.1
1 EDB exploit
8.6
CVSSv3
CVE-2016-4264
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote malicious users to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunct...
Adobe Coldfusion
1 EDB exploit
2 Github repositories
7.5
CVSSv3
CVE-2019-10266
An issue exists in Ahsay Cloud Backup Suite prior to 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.
Ahsay Cloud Backup Suite
1 EDB exploit
5
CVSSv3
CVE-2017-7457
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
Moxa Mx-aopc Server 1.5
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »