// For flags

CVE-2018-8819

WebCTRL Out-Of-Band XML Injection

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.

Se ha descubierto un problema de XEE (XML External Entity) en Automated Logic Corporation (ALC) WebCTRL en versiones 6.0, 6.1 y 6.5. Un atacante no autenticado podría introducir entradas maliciosas a WebCTRL y un analizador XML mal configurado permitirá que la aplicación revele el contenido total de los archivos del sistema operativo del servidor web subyacente mediante la cabecera HTTP "X-Wap-Profile".

WebCTRL suffers from an out-of-band XML external entity injection vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-03-20 CVE Reserved
  • 2018-06-09 CVE Published
  • 2024-01-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Carrier
Search vendor "Carrier"
Automatedlogic Webctrl
Search vendor "Carrier" for product "Automatedlogic Webctrl"
6.0
Search vendor "Carrier" for product "Automatedlogic Webctrl" and version "6.0"
-
Affected
Carrier
Search vendor "Carrier"
Automatedlogic Webctrl
Search vendor "Carrier" for product "Automatedlogic Webctrl"
6.1
Search vendor "Carrier" for product "Automatedlogic Webctrl" and version "6.1"
-
Affected
Carrier
Search vendor "Carrier"
Automatedlogic Webctrl
Search vendor "Carrier" for product "Automatedlogic Webctrl"
6.5
Search vendor "Carrier" for product "Automatedlogic Webctrl" and version "6.5"
-
Affected