vendor:
Visual Basic 2010 Express
by:
ZwX
7.5
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: Visual Basic 2010 Express
Affected Version From: 10.0.30319.1 RTMRel
Affected Version To: 10.0.30319.1 RTMRel
Patch Exists: NO
Related CWE:
CPE: a:microsoft:visual_basic:2010_express
Platforms Tested: Windows 7
2019
Microsoft Visual Basic 2010 Express – XML External Entity Injection
This exploit allows an attacker to inject external entities into an XML document, potentially leading to information disclosure or denial of service.
Mitigation:
To mitigate this vulnerability, ensure that user-supplied XML data is properly validated and sanitized.