vendor:
Enterprise Mode Site List Manager
by:
John Page (aka hyp3rlinx)
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: Enterprise Mode Site List Manager
Affected Version From: 1
Affected Version To: 2
Patch Exists: N/A
Related CWE: N/A
CPE: a:microsoft:enterprise_mode_site_list_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
N/A
Microsoft Windows Enterprise Mode Site List Manager XXE
Versions 1 and 2 of Microsoft Enterprise Mode Site List Manager allow local file exfiltration to a remote attacker controlled server, if the user is tricked into using an attacker supplied '.emie' site list manager file type.
Mitigation:
N/A