Vulnerability CVE-2017-9355


Published: 2017-06-07

Description:
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.

See advisories in our WLB2 database:
Topic
Author
Date
High
Subsonic 6.1.1 XML External Entity Attack
hyp3rlinx
06.06.2017

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Subsonic -> Subsonic 

 References:
http://hyp3rlinx.altervista.org/advisories/SUBSONIC-XML-EXTERNAL-ENITITY.txt
http://packetstormsecurity.com/files/142795/Subsonic-6.1.1-XML-External-Entity-Attack.html

Copyright 2024, cxsecurity.com

 

Back to Top