Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-13706

Опубликовано: 10 окт. 2017
Источник: nvd
CVSS3: 9.9
CVSS2: 6.5
EPSS Низкий

Описание

XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lansweeper:lansweeper:*:*:*:*:*:*:*:*
Версия до 6.0.100.29 (включая)

EPSS

Процентиль: 80%
0.0141
Низкий

9.9 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.9
github
больше 3 лет назад

XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.

EPSS

Процентиль: 80%
0.0141
Низкий

9.9 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-611