PT-2017-7266 · Paessler · Prtg Network Monitor

Publicado

2017-01-23

·

Atualizado

2017-01-25

·

CVE-2015-7743

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PRTG Network Monitor versions prior to 16.2.23.3077/3078
Description The issue allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file. This is related to an XML external entity vulnerability.
Recommendations For versions prior to 16.2.23.3077/3078, update to version 16.2.23.3077/3078 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP XML/REST Value sensor to minimize the risk of exploitation.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7743

Produtos afetados

Prtg Network Monitor