vendor:
NovaPACS Diagnostics Viewer
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: NovaPACS Diagnostics Viewer
Affected Version From: 8.5.19.75
Affected Version To: 8.5.19.75
Patch Exists: NO
Related CWE: N/A
CPE: NovaRad Corporation:NovaPACS_Diagnostics_Viewer:8.5.19.75
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN)
2018
NovaRad NovaPACS Diagnostics Viewer 8.5 – XML External Entity Injection (File Disclosure)
NovaPACS suffers from an unauthenticated XML External Entity (XXE) injection vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data from the affected node via out-of-band (OOB) channel attack. The vulnerability is triggered when importing XML format preferences within the settings submenu.
Mitigation:
Disable external entity references in XML documents, and disable DTDs entirely if possible.