215
VMScore

CVE-2018-16252

Published: 05/09/2018 Updated: 04/12/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fspro event log explorer 4.6.1.2115

Exploits

# Title: FsPro Labs Event Log Explorer v4612115 - XML External Entity Injection # Author: hyp3rlinx # Date: 2018-09-01 # Vendor: wwweventlogxpcom # Software: eventlogxpcom/downloadphp # Affected Component: elexexe # CVE: N/A # Description: # Upon opening a specially crafted ELX file in Event Log Explorer, remote attackers # can p ...
FsPro Labs Event Log Explorer version 4612115 suffers from an XML external entity injection vulnerability ...