4

CVE-2015-2346

Exploit
XML external entity (XXE) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote authenticated users to read arbitrary files via the req parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Seq Analyst Version <= v200r002c03lg0001spc100
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.17% 0.633
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://packetstormsecurity.com/files/131459/Huawei-SEQ-Analyst-XXE-Injection.html
http://seclists.org/fulldisclosure/2015/Apr/42
Exploit