Get a Pentest and security assessment of your IT network.

2021-current

CVE-2015-0581 – The XML parser in Cisco Prime Service Catalog before 10.1 allows remote a

The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0581

Reference (s):

  • BID:72350
  • URL: http://www.securityfocus.com/bid/72350
  • CISCO:20150128 Cisco Prime Service Catalog XML External Entity Processing Vulnerability
  • URL: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-psc-xmlee
  • SECTRACK:1031658
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-8509 - The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) all

2021-current

CVE-2020-0298 - In Bluetooth, there is a possible control over Bluetooth enabled state du

2021-current

CVE-2020-14316 - A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances