5.5
CVSSv3

CVE-2017-8918

Published: 12/09/2017 Updated: 21/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows malicious users to remotely view local files via a crafted template.xml file.

Vulnerable Product Search on Vulmon Subscribe to Product

blackwave dive assistant 8.0

Exploits

[+] Exploit Title: Dive Assistant - Template Builder XXE Injection [+] Date: 12-05-2017 [+] Exploit Author: Trent Gordon [+] Vendor Homepage: wwwblackwavecom/ [+] Software Link: wwwdiveassistantcom/Products/DiveAssistantDesktop/indexaspx [+] Version: 80 [+] Tested on: Windows 7 SP1, Windows 10 [+] CVE: CVE-2017-8918 1 Vulnerab ...