Логотип exploitDog
bind:CVE-2018-25142
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-25142

Количество 2

Количество 2

nvd логотип

CVE-2018-25142

около 2 месяцев назад

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-ghwc-hrr9-vj2w

около 2 месяцев назад

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-25142

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-ghwc-hrr9-vj2w

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу