vendor:
iWay Data Quality Suite Web Console
by:
Sureshbabu Narvaneni
7.5
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: iWay Data Quality Suite Web Console
Affected Version From: 10.6.1.ga
Affected Version To: 10.6.1.ga
Patch Exists: NO
Related CWE: N/A
CPE: a:information_builders:iway_data_quality_suite_web_console
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win7 Enterprise x86/Kali Linux 4.12 i686
2018
iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20 – XML External Entity Injection
iWay Data Quality Suite Web Console provides web services features. As there is no validation present on the web services featured by product while processing the user input an attacker can easily inject external entities in the SOAP request and can achieve the successful Remote Code Execution on the server.
Mitigation:
Validate user input and restrict the use of external entities in the SOAP request.