7.5
CVSSv2

CVE-2018-11586

Published: 05/06/2018 Updated: 31/07/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

searchblox searchblox 8.6.7

Exploits

# Exploit Title: SearchBlox 867 Out-Of-Band XML eXternal Entity (OOB-XXE) # Exploit Author: Ahmet GUREL, Canberk BOLAT # Software Link: wwwsearchbloxcom/ # Version: < = SearchBlox Version 867 # Platform: Java # Tested on: Windows # CVE: CVE-2018-11586 # 1 DETAILS An XML External Entity attack is a type of attack against an appli ...
SearchBlox version 867 suffers from an XML external entity injection vulnerability ...