CVE-2018-2392: SAP Internet Graphics Server (IGS) – XML External Entity Injection

CVE-2018-2392: SAP Internet Graphics Server (IGS) - XML External Entity Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2018-2392: SAP Internet Graphics Server (IGS) – XML External Entity Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2018-2392: SAP Internet Graphics Server (IGS) – XML External Entity Injection

漏洞描述

SAP Internet Graphics Servers (IGS) running versions 7.20, 7.20EXT, 7.45, 7.49, or 7.53 has two XML external entity injection (xxe) vulnerabilities within the XMLCHART page – CVE-2018-2392 and CVE-2018-2393. These vulnerabilities occur due to a lack of appropriate validation on the Extension HTML tag when submitting a POST request to the XMLCHART page to generate a new chart.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享