CVE-2018-8819
PoC —CVSS 3.0
7.5 high
EPSS
3%p87
Published
()
Modified
Description
An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.
- Vendors
- carrier
- Products
- automatedlogic webctrl
- Weakness
- CWE-611
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.